cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Malwarebytes Anti-Malware
www.malwarebytes.org

Date de l'analyse: 21/07/2016
Heure de l'analyse: 14:21
Fichier journal: Rapport MBAM.txt
Administrateur: Oui

Version: 2.2.1.1043
Base de données de programmes malveillants: v2016.07.21.02
Base de données de rootkits: v2016.05.27.01
Licence: Essai
Protection contre les programmes malveillants: Activé
Protection contre les sites Web malveillants: Activé
Autoprotection: Désactivé

Système d'exploitation: Windows 10
Processeur: x86
Système de fichiers: NTFS
Utilisateur: nicon

Type d'analyse: Analyse des menaces
Résultat: Terminé
Objets analysés: 344651
Temps écoulé: 8 min, 44 s

Mémoire: Activé
Démarrage: Activé
Système de fichiers: Activé
Archives: Activé
Rootkits: Désactivé
Heuristique: Activé
PUP: Activé
PUM: Activé

Processus: 0
(Aucun élément malveillant détecté)

Modules: 0
(Aucun élément malveillant détecté)

Clés du Registre: 17
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CF1FA42B-52C5-4347-AB88-7FAD34EB48E2}, En quarantaine, [9c0a27ffb2e8c373f2afd8ec5aa9728e],
PUP.Optional.WinZipMalwareProtector, HKLM\SOFTWARE\MICROSOFT\TRACING\WinZipMalwareProtector_RASAPI32, En quarantaine, [7036c75ff7a3e551afa902e3d82be31d],
PUP.Optional.WinZipMalwareProtector, HKLM\SOFTWARE\MICROSOFT\TRACING\WinZipMalwareProtector_RASMANCS, En quarantaine, [efb7b76fb1e972c45afef5f03bc8728e],
PUP.Optional.PriceFountain, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{2687AD34-18E8-42DB-A25F-9983E6ABBF4D}, Supprimer au redémarrage, [4660d5519604c86e7fcbf5fbbe45c53b],
PUP.Optional.WinZipMalwareProtector, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WinZip Malware Protector, En quarantaine, [f4b2af779901ca6c83d8e203c53e9f61],
PUP.Optional.InstallCore, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\csastats, En quarantaine, [941231f5faa040f6995dbc3ec53ed52b],
PUP.Optional.InstallCore, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\ICSW1.22, En quarantaine, [c6e06eb8b1e94aec3232f5b25ca745bb],
PUP.Optional.DriverRestore, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\DRIVERRESTORE, En quarantaine, [475f879f8a10f04605560be9649fb749],
PUP.Optional.DriverAgentPlus, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\ESUPPORT.COM\DriverAgent, En quarantaine, [1f87c95d4654270f8d2f8679b64d50b0],
PUP.Optional.WinYahoo, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CF1FA42B-52C5-4347-AB88-7FAD34EB48E2}, En quarantaine, [c4e27fa74555b2843e6141838c77fe02],
PUP.Optional.WinYahoo, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2F23AB71-4AC6-41F2-A955-EA576E553146}, En quarantaine, [c4e29393d7c32511feabfacffe040bf5],
PUP.Optional.ProductSetup, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\PRODUCTSETUP, En quarantaine, [941274b2debc63d32eebe8c937cc758b],
PUP.Optional.InstallCore, HKU\S-1-5-21-2936584411-1782327938-59671983-1006\SOFTWARE\csastats, En quarantaine, [7b2b5bcbbcde87af896d31c9f2117c84],
PUP.Optional.InstallCore, HKU\S-1-5-21-2936584411-1782327938-59671983-1006\SOFTWARE\ICSW1.22, En quarantaine, [02a48f973862c2740460d1d66a99ba46],
PUP.Optional.PriceFountain, HKU\S-1-5-21-2936584411-1782327938-59671983-1006\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\INKWELLSTRATOCUMULI, En quarantaine, [574f1313940639fd42df78886e96d927],
PUP.Optional.PriceFountain, HKU\S-1-5-21-2936584411-1782327938-59671983-1006\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{18186AD9-64BC-E9CF-DBC3-7A35414EBE65}, En quarantaine, [10960f17f6a40c2ab26f768ae123d030],
PUP.Optional.ProductSetup, HKU\S-1-5-21-2936584411-1782327938-59671983-1006\SOFTWARE\PRODUCTSETUP, En quarantaine, [92145bcb3b5fc0762beee8c9fe0506fa],

Valeurs du Registre: 9
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CF1FA42B-52C5-4347-AB88-7FAD34EB48E2}|URL, https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f[9c0a27ffb2e8c373f2afd8ec5aa9728e]D4%26b[9c0a27ffb2e8c373f2afd8ec5aa9728e]DIE%26cc[9c0a27ffb2e8c373f2afd8ec5aa9728e]D%26pa[9c0a27ffb2e8c373f2afd8ec5aa9728e]DWincy%26cd[9c0a27ffb2e8c373f2afd8ec5aa9728e]D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr[9c0a27ffb2e8c373f2afd8ec5aa9728e]D386223762%26a[9c0a27ffb2e8c373f2afd8ec5aa9728e]Dwncy_adsrch_16_29%26os_ver[9c0a27ffb2e8c373f2afd8ec5aa9728e]D10.0%26os[9c0a27ffb2e8c373f2afd8ec5aa9728e]DWindowsEn quarantaineB10En quarantaineBHome&p={searchTerms}, %4, %5
PUP.Optional.PriceFountain, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{2687AD34-18E8-42DB-A25F-9983E6ABBF4D}|Path, \EmycoInkwellStratocumuliV2, Supprimer au redémarrage, [4660d5519604c86e7fcbf5fbbe45c53b]
PUP.Optional.DriverRestore, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\DRIVERRESTORE|FirstScanDateTime, 2016-07-20T10:45:45.4358875+02:00, En quarantaine, [475f879f8a10f04605560be9649fb749]
PUP.Optional.WinYahoo, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CF1FA42B-52C5-4347-AB88-7FAD34EB48E2}|URL, https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f[c4e27fa74555b2843e6141838c77fe02]D4%26b[c4e27fa74555b2843e6141838c77fe02]DIE%26cc[c4e27fa74555b2843e6141838c77fe02]D%26pa[c4e27fa74555b2843e6141838c77fe02]DWincy%26cd[c4e27fa74555b2843e6141838c77fe02]D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr[c4e27fa74555b2843e6141838c77fe02]D386223762%26a[c4e27fa74555b2843e6141838c77fe02]Dwncy_adsrch_16_29%26os_ver[c4e27fa74555b2843e6141838c77fe02]D10.0%26os[c4e27fa74555b2843e6141838c77fe02]DWindowsEn quarantaineB10En quarantaineBHome&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2f23ab71-4ac6-41f2-a955-ea576e553146}|URL, https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_16_29¶m1=1¶m2=f[c4e29393d7c32511feabfacffe040bf5]D4%26b[c4e29393d7c32511feabfacffe040bf5]DIE%26cc[c4e29393d7c32511feabfacffe040bf5]Dfr%26pa[c4e29393d7c32511feabfacffe040bf5]DWincy%26cd[c4e29393d7c32511feabfacffe040bf5]D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0StCyCyCtBtN1L2XzutAtFtBtAtFtCtFtAtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr[c4e29393d7c32511feabfacffe040bf5]D1080072568%26a[c4e29393d7c32511feabfacffe040bf5]Dwbf_ir_16_29%26os_ver[c4e29393d7c32511feabfacffe040bf5]D10.0%26os[c4e29393d7c32511feabfacffe040bf5]DWindowsEn quarantaineB10En quarantaineBHome&p={searchTerms}, %4, %5
PUP.Optional.ProductSetup, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\PRODUCTSETUP|tb, 0O1O1R1D1R2Y1K0V1E1M2S1R1T1B, En quarantaine, [941274b2debc63d32eebe8c937cc758b]
PUP.Optional.PriceFountain, HKU\S-1-5-21-2936584411-1782327938-59671983-1006\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\InkwellStratocumuli|DisplayName, PriceFountain, En quarantaine, [574f1313940639fd42df78886e96d927]
PUP.Optional.PriceFountain, HKU\S-1-5-21-2936584411-1782327938-59671983-1006\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{18186AD9-64BC-E9CF-DBC3-7A35414EBE65}|DisplayName, Update for PriceFountain, En quarantaine, [10960f17f6a40c2ab26f768ae123d030]
PUP.Optional.ProductSetup, HKU\S-1-5-21-2936584411-1782327938-59671983-1006\SOFTWARE\PRODUCTSETUP|tb, 0X1F1T1V1G1G, En quarantaine, [92145bcb3b5fc0762beee8c9fe0506fa]

Données du Registre: 2
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=fMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[3274f1358911c472d540255483815fa1]D1%26bMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[3274f1358911c472d540255483815fa1]DIE%26ccMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[3274f1358911c472d540255483815fa1]D%26paMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[3274f1358911c472d540255483815fa1]DWincy%26cdMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[3274f1358911c472d540255483815fa1]D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26crMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[3274f1358911c472d540255483815fa1]D386223762%26aMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[3274f1358911c472d540255483815fa1]Dwncy_adsrch_16_29%26os_verMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[3274f1358911c472d540255483815fa1]D10.0%26osMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[3274f1358911c472d540255483815fa1]DWindowsBon : (www.google.com)B10Bon : (www.google.com)BHome, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-2936584411-1782327938-59671983-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=fMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[06a08a9cafeba98d070ca8d13acae41c]D1%26bMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[06a08a9cafeba98d070ca8d13acae41c]DIE%26ccMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[06a08a9cafeba98d070ca8d13acae41c]D%26paMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[06a08a9cafeba98d070ca8d13acae41c]DWincy%26cdMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[06a08a9cafeba98d070ca8d13acae41c]D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26crMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[06a08a9cafeba98d070ca8d13acae41c]D386223762%26aMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[06a08a9cafeba98d070ca8d13acae41c]Dwncy_adsrch_16_29%26os_verMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[06a08a9cafeba98d070ca8d13acae41c]D10.0%26osMauvais : (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsrch_16_29¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3D%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0E0CyBtDzytCtDyBzzzy0ByC0F0E0AtN0D0Tzu0CtCyCyCtAtN1L2XzutAtFtByEtFtAtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDtBtByEtCyDtByDtGtCtDyByBtG0A0DtAtCtGyD0F0BtBtGtA0A0B0CtDtB0A0Czyzy0BtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyDzyyByByByCzztG0DzyyCtDtGyEyDyBzztGzyyDyByDtGyB0B0CtByE0CyDyD0F0EyCtB2QtN0A0LzuyE%26cr%3D386223762%26a%3Dwncy_adsrch_16_29%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome),Remplacé,[06a08a9cafeba98d070ca8d13acae41c]DWindowsBon : (www.google.com)B10Bon : (www.google.com)BHome, %4, %5

Dossiers: 7
PUP.Optional.AmazonTB, C:\Users\Emyco\AppData\Roaming\Mozilla\Firefox\Profiles\ut365xod.default\jetpack\abb@amazon.com, En quarantaine, [4b5baf77e9b1e35320d938748280bb45],
PUP.Optional.AmazonTB, C:\Users\Emyco\AppData\Roaming\Mozilla\Firefox\Profiles\ut365xod.default\jetpack\abb@amazon.com\simple-storage, En quarantaine, [4b5baf77e9b1e35320d938748280bb45],
PUP.Optional.AmazonTB, C:\Users\nicon\AppData\Roaming\Mozilla\Firefox\Profiles\rogmh5tg.default\jetpack\abb@amazon.com, En quarantaine, [8125b274ebaf270f7881fab29b679a66],
PUP.Optional.AmazonTB, C:\Users\nicon\AppData\Roaming\Mozilla\Firefox\Profiles\rogmh5tg.default\jetpack\abb@amazon.com\simple-storage, En quarantaine, [8125b274ebaf270f7881fab29b679a66],
PUP.Optional.AdvancedSystemProtector, C:\Users\nicon\AppData\Local\Systweak\Advanced System Protector, En quarantaine, [2e78b96d4852979fc0715f6341c1f30d],
PUP.Optional.DriverRestore, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore, En quarantaine, [d3d39393b1e9c670bfdc9a2c13efef11],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],

Fichiers: 26
PUP.Optional.PriceFountain, C:\Users\Emyco\AppData\Local\Temp\SubdepartmentWavelengths.dll, En quarantaine, [3b6bf234dbbff343aae59a038a779c64],
PUP.Optional.383Media, C:\Users\nicon\AppData\Local\Temp\DRHelper_uninstallComplete.exe, En quarantaine, [b8ee0a1c445681b5e19895d0de23649c],
Rogue.Link, C:\Users\Emyco\Desktop\Privacy Protector Plus.lnk, En quarantaine, [7630c462cbcf4ee820f6a76557ac817f],
PUP.Optional.AmazonTB, C:\Users\Emyco\AppData\Roaming\Mozilla\Firefox\Profiles\ut365xod.default\extensions\abb@amazon.com.xpi, En quarantaine, [c4e212140199ea4ca0971087ec1731cf],
PUP.Optional.AmazonTB, C:\Users\nicon\AppData\Roaming\Mozilla\Firefox\Profiles\rogmh5tg.default\extensions\abb@amazon.com.xpi, En quarantaine, [01a55ec81b7fc37369ce504742c1a957],
PUP.Optional.PriceFountain, C:\Windows\System32\Tasks\EmycoInkwellStratocumuliV2, En quarantaine, [396d1115bbdf67cfb89ee7fcf310a858],
PUP.Optional.AmazonTB, C:\Users\Emyco\AppData\Roaming\Mozilla\Firefox\Profiles\ut365xod.default\jetpack\abb@amazon.com\simple-storage\store.json, En quarantaine, [4b5baf77e9b1e35320d938748280bb45],
PUP.Optional.AmazonTB, C:\Users\nicon\AppData\Roaming\Mozilla\Firefox\Profiles\rogmh5tg.default\jetpack\abb@amazon.com\simple-storage\store.json, En quarantaine, [8125b274ebaf270f7881fab29b679a66],
PUP.Optional.AdvancedSystemProtector, C:\Users\nicon\AppData\Local\Systweak\Advanced System Protector\ScanEngineErrorLog.txt, En quarantaine, [2e78b96d4852979fc0715f6341c1f30d],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\Rkey.dat, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\amazon.fr .lnk, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\amazon.fr.ico, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\amazon.fr.lnk, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\amazon.fr.smenu.URL, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\amazon.fr.tbar.URL, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\Booking .lnk, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\Booking.ico, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\Booking.lnk, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\Booking.smenu.URL, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\Booking.tbar.URL, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\CosponsorshipsRecons.dat, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.PriceFountain.Gen, C:\Users\Emyco\AppData\Local\InkwellStratocumuli\PaniclesYaks.exe, En quarantaine, [4264dc4ab9e185b178001d7f010359a7],
PUP.Optional.ShortcutHijack, C:\Users\Emyco\Desktop\amazon.fr.URL, En quarantaine, [bbebc066574362d452360a93a36129d7],
PUP.Optional.ShortcutHijack, C:\Users\Emyco\Desktop\Booking.URL, En quarantaine, [287e58cecfcb1e18b5d3138ad62e8a76],
PUP.Optional.WinYahoo, C:\Users\nicon\AppData\Roaming\Mozilla\Firefox\Profiles\rogmh5tg.default\prefs.js, Bon : (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Mauvais : (user_pref("browser.startup.homepage", "https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy), Remplacé,[6e3830f60199c670c753e5bbb64e3fc1]
PUP.Optional.WinYahoo, C:\Users\nicon\AppData\Roaming\Mozilla\Firefox\Profiles\rogmh5tg.default\searchplugins\yahoo! powered.xml, En quarantaine, [04a235f1207a83b3af8f5448ed17a65a],

Secteurs physiques: 0
(Aucun élément malveillant détecté)


(end)

Publicité


Signaler le contenu de ce document

Publicité