cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Malwarebytes
www.malwarebytes.com

-Détails du journal-
Date de l'analyse: 18/10/2020
Durée d'analyse: 13:55
Fichier journal: d44cf21a-1138-11eb-bc22-74852a1e8eac.json

-Informations du logiciel-
Version: 4.2.1.89
Version de composants: 1.0.1070
Version de pack de mise à jour: 1.0.31558
Licence: Essai

-Informations système-
Système d'exploitation: Windows 10 (Build 19041.572)
Processeur: x64
Système de fichiers: NTFS
Utilisateur: DESKTOP-MELT09Q\boris

-Résumé de l'analyse-
Type d'analyse: Analyse des menaces
Analyse lancée par: Manuel
Résultat: Terminé
Objets analysés: 293358
Menaces détectées: 33
Menaces mises en quarantaine: 33
Temps écoulé: 1 min, 19 s

-Options d'analyse-
Mémoire: Activé
Démarrage: Activé
Système de fichiers: Activé
Archives: Activé
Rootkits: Désactivé
Heuristique: Activé
PUP: Détection
PUM: Détection

-Détails de l'analyse-
Processus: 0
(Aucun élément malveillant détecté)

Module: 0
(Aucun élément malveillant détecté)

Clé du registre: 12
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4AD348D5-63C4-4C58-8121-9FE644F5379C}, En quarantaine, 7, 784919, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{4AD348D5-63C4-4C58-8121-9FE644F5379C}, En quarantaine, 7, 784919, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\MICROSOFT\WINDOWS\WDI\SrvHost, En quarantaine, 7, 784919, 1.0.31558, , ame, , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Microsoft\Windows\Application Experience\STARTUPCHECKLIBRARY, En quarantaine, 7, 735770, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{BEC78C0D-1436-44CE-9855-BFF26DF1B37E}, En quarantaine, 7, 735770, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{BEC78C0D-1436-44CE-9855-BFF26DF1B37E}, En quarantaine, 7, 735770, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{D052C35E-7EC0-490E-ACF1-E3DEA86BF9E1}, En quarantaine, 7, 780231, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{D052C35E-7EC0-490E-ACF1-E3DEA86BF9E1}, En quarantaine, 7, 780231, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\MICROSOFT\WINDOWS\WININET\Winlogui, En quarantaine, 7, 780231, 1.0.31558, , ame, , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Microsoft\Windows\Windows Error Reporting\winrmsrv, En quarantaine, 7, 780529, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5AD45DB2-25F9-4F97-AD65-FB30EE604D01}, En quarantaine, 7, 780529, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{5AD45DB2-25F9-4F97-AD65-FB30EE604D01}, En quarantaine, 7, 780529, , , , , ,

Valeur du registre: 6
Trojan.BitCoinMiner, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{0CD69ABF-C71C-4789-85F7-B8569932D5AE}, En quarantaine, 279, 840273, 1.0.31558, , ame, , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4AD348D5-63C4-4C58-8121-9FE644F5379C}|PATH, En quarantaine, 7, 784920, 1.0.31558, , ame, , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5AD45DB2-25F9-4F97-AD65-FB30EE604D01}|PATH, En quarantaine, 7, 780528, 1.0.31558, , ame, , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{BEC78C0D-1436-44CE-9855-BFF26DF1B37E}|PATH, En quarantaine, 7, 782993, 1.0.31558, , ame, , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{D052C35E-7EC0-490E-ACF1-E3DEA86BF9E1}|PATH, En quarantaine, 7, 780232, 1.0.31558, , ame, , ,
PUP.Optional.TorrentSearch.ChrPRST, HKU\S-1-5-21-693528651-4183323470-2030038019-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|afbpdhiclgghnffhkinjikglgmolhpee, En quarantaine, 9033, 452683, , , , , ,

Données du registre: 0
(Aucun élément malveillant détecté)

Flux de données: 0
(Aucun élément malveillant détecté)

Dossier: 1
PUP.Optional.TorrentSearch.ChrPRST, C:\USERS\BORIS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\EXTENSIONS\afbpdhiclgghnffhkinjikglgmolhpee, En quarantaine, 9033, 452683, 1.0.31558, , ame, , ,

Fichier: 14
PUP.Optional.Booking, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\BOOKING.COM.LNK, En quarantaine, 8004, 347183, 1.0.31558, , ame, , 07177C92E73C72352C2143BC9B32812C, A09C78BDC8956EFA8AD2AA23E5D30AC6FD0093E28CB07DD47DB2D306E418058B
Trojan.Agent, C:\WINDOWS\SYSTEM32\TASKS\MICROSOFT\WINDOWS\WDI\SRVHOST, En quarantaine, 7, 784919, , , , , 0C1553446E82EBB7B7845859A481205D, DADF221FA82CD88E15D169C92B122767FFD94F7001209E201445BF83E0E34E70
PUP.Optional.Restoro, C:\WINDOWS\RESTORO.INI, En quarantaine, 11323, 551609, 1.0.31558, , ame, , 6700D658A4FB994F77738703150B3DC9, FFBD2ADC6615932D64AB1DBCDEAADB6E9266D60D3C66A59A128166B4E88534CA
Trojan.Agent, C:\WINDOWS\SYSTEM32\TASKS\MICROSOFT\WINDOWS\APPLICATION EXPERIENCE\STARTUPCHECKLIBRARY, En quarantaine, 7, 735770, 1.0.31558, , ame, , A8894E586C1BA76BB3256FEE5750C1A6, 7228AE350E90C4C042D8F384F4998D640401565EA9EE254486259AF8C46C00F0
Trojan.Agent, C:\WINDOWS\SYSTEM32\TASKS\MICROSOFT\WINDOWS\WININET\WINLOGUI, En quarantaine, 7, 780231, , , , , 45803D116A9294D77B4ECB00437FFB52, 3EFB2316495D6351815700C2DAB2ADCD5A6528AE6497400641D8364BAC458FC1
Trojan.Agent, C:\WINDOWS\SYSTEM32\TASKS\MICROSOFT\WINDOWS\WINDOWS ERROR REPORTING\WINRMSRV, En quarantaine, 7, 780529, 1.0.31558, , ame, , 72281D24C9534DA5325944B2A6861912, A7B2920703E0EC865AEB8CEE2076AAE7FEEE53311A02CFB531F9F8ACF4075961
PUP.Optional.TorrentSearch.ChrPRST, C:\USERS\BORIS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Remplacé, 9033, 452683, , , , , 3DC2DB758900E65E34DD2F0DAB4255DE, D69539C6D24ED2433C0D69443D7DBCF94A7A9DD6031F0F601D9DD55358573505
PUP.Optional.Restoro, C:\USERS\BORIS\APPDATA\ROAMING\ZHP\QUARANTINE\ZHPCLEANER\BU_.EXE, En quarantaine, 11323, 551611, 1.0.31558, , ame, , 660E601D13769A66615303E7588C872F, C214C962FCF1A1072EF5641480E1721F1246DEE49EDCB4D82E6CB0E48933CDD0
PUP.Optional.Restoro, C:\USERS\BORIS\APPDATA\ROAMING\ZHP\QUARANTINE\ZHPCLEANER\RESTOROSETUP64[1].EXE, En quarantaine, 11323, 551611, 1.0.31558, , ame, , D302B0E6E9E1DE8FA983176370BF81C1, 4F1773B380F37C167AE167B1A3419432199E5B2CCD3EDC26FF90F136422E7E2B
PUP.Optional.Restoro, C:\USERS\BORIS\APPDATA\ROAMING\ZHP\QUARANTINE\ZHPCLEANER\RESTOROSERVICESETUP64[1].EXE, En quarantaine, 11323, 551611, 1.0.31558, , ame, , 650EAEB80D828569D34E6B6BDC2910A4, 6E09B0D7C7EC9FEAA5B6F0CB153EBE28E7BC34451D558FCD4CDE7601D3EEDDF1
PUP.Optional.Restoro, C:\USERS\BORIS\APPDATA\ROAMING\ZHP\QUARANTINE\ZHPCLEANER\AU_.EXE, En quarantaine, 11323, 551611, 1.0.31558, , ame, , AA3BAF774707DAB7071A3789FEB0C557, BC077428864ED113D853C27A8B22626B355DB3D8C8F8B20BBE57634EB2818509
PUP.Optional.AdvancedSystemCare, C:\USERS\BORIS\DESKTOP\IOBIT_TOOLBOX\TOOLS\TBFFSWEEP.DLL, En quarantaine, 8243, 396386, 1.0.31558, , ame, , 1098EBC612F13A731B94045B193CE099, ED6A18B2CFB21D28D68EC37BA464720D7DA9FCEEEA7C7303C2603E254530AEB4
PUP.Optional.Outbyte, C:\USERS\BORIS\DESKTOP\0X80080005_REPAIR-SETUP.EXE, En quarantaine, 13682, 799072, 1.0.31558, , ame, , A91A87A55DA06E2A3DD2C1045CAEB869, 23AACB3ED2347F6ABE455131CD42AE2848FE430E2BFB0B75D400556732350523
PUP.Optional.AdvancedSystemCare, C:\USERS\BORIS\DESKTOP\IOBIT_TOOLBOX\TOOLS\TBFILESWEEP.DLL, En quarantaine, 8243, 396386, 1.0.31558, , ame, , 5399BEEA45D999ADC4645B03FE303E0C, 0E7FBC7CB22EF931B7287C91C9F6E5AB240745003F6046DB3684DA051A0675CD

Secteur physique: 0
(Aucun élément malveillant détecté)

WMI: 0
(Aucun élément malveillant détecté)


(end)

Publicité


Signaler le contenu de ce document

Publicité