Malwarebytes Anti-Malware www.malwarebytes.org Date de l'analyse: 03/08/2015 Heure de l'analyse: 14:17 Fichier journal: MBAM.txt Administrateur: Oui Version: 2.1.8.1057 Base de données de programmes malveillants: v2015.08.03.03 Base de données de rootkits: v2015.07.30.01 Licence: Gratuit Protection contre les programmes malveillants: Désactivé Protection contre les sites Web malveillants: Désactivé Autoprotection: Désactivé Système d'exploitation: Windows 8.1 Processeur: x64 Système de fichiers: NTFS Utilisateur: Elise Type d'analyse: Analyse des menaces Résultat: Terminé Objets analysés: 341392 Temps écoulé: 27 min, 9 s Mémoire: Activé Démarrage: Activé Système de fichiers: Activé Archives: Activé Rootkits: Activé Heuristique: Activé PUP: Activé PUM: Activé Processus: 1 PUP.Optional.ServiceRNDM.A, C:\Program Files (x86)\Testy Option\Testy Option.exe, 1032, Supprimer au redémarrage, [9bd4b84cbfcc80b6336080478180c739] Modules: 0 (Aucun élément malveillant détecté) Clés du registre: 18 PUP.Optional.ServiceRNDM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Testy Option, En quarantaine, [9bd4b84cbfcc80b6336080478180c739], PUP.Optional.WinYahoo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, En quarantaine, [4b2440c44d3e171f53b5c5da4db7bb45], PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32LDR, En quarantaine, [9dd2a262276411259bef3d64e51f7090], PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, En quarantaine, [115ecd37810a44f26c5abdd0ef15e917], PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, En quarantaine, [e58ad133a5e60333bb0a9eefbf4506fa], PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, En quarantaine, [c1aedb29a6e5e650e54c663b020232ce], PUP.Optional.CrossRider.C, HKLM\SOFTWARE\WOW6432NODE\APPDATALOW\SOFTWARE\Crossrider, En quarantaine, [1956ca3a741772c4cc2e71a425de8a76], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\adpeheiliennogfclcgmchdfdmafjegc, En quarantaine, [d897b25253381c1a67caa8f38282f30d], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ehhlaekjfiiojlddgndcnefflngfmhen, En quarantaine, [e887a2622566d95d1f0a0035b54eee12], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{ff148bd5}, En quarantaine, [71fe41c3e6a5dc5a5344148ba75dc13f], PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, En quarantaine, [beb13dc726650333f33e00a127dd60a0], PUP.Optional.SuperOptimizer.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, En quarantaine, [3a35dc28cfbc3afc37eb1390f0148080], PUP.Optional.Crossrider.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, En quarantaine, [5d122fd59eedc27434ca069554b0cc34], PUP.Optional.Shopperz.A, HKU\S-1-5-18\SOFTWARE\{1A945540-4E69-4CFB-A200-900B2040E440}, En quarantaine, [a5ca7b89117a03336317f8b036cea25e], PUP.Optional.Shopperz.A, HKU\S-1-5-19\SOFTWARE\{1A945540-4E69-4CFB-A200-900B2040E440}, En quarantaine, [a4cbaa5a0e7ded49136743657c88bb45], PUP.Optional.Shopperz.A, HKU\S-1-5-20\SOFTWARE\{1A945540-4E69-4CFB-A200-900B2040E440}, En quarantaine, [135c758f177486b0a6d4a107f212966a], PUP.Optional.Iminent.A, HKU\S-1-5-21-2298773659-1734756943-2230792534-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\Iminent, En quarantaine, [91de7a8aaddebc7afbf69eae35cef20e], PUP.Optional.Shopperz.A, HKU\S-1-5-21-2298773659-1734756943-2230792534-1001\SOFTWARE\{1A945540-4E69-4CFB-A200-900B2040E440}, En quarantaine, [c4ab0df7ff8c66d0a6d430783bc91ce4], Valeurs du registre: 21 PUP.Optional.WinYahoo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, http://fr.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_vit_15_26¶m1=1¶m2=fEn quarantaineD4%26bEn quarantaineDIE%26ccEn quarantaineDfr%26paEn quarantaineDWincy%26cdEn quarantaineD2XzuyEtN2Y1L1Qzu0FtDyByCtC0CtAzzyEyEyCyBtD0FtB0BtN0D0Tzu0StCtByCzztN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StCtAyE0C0AyEtAtCtGyDyE0B0CtGtBzzzyzztGtDtAtBtBtGtDzytD0EyDzz0Czy0AyByEzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtAzy0E0DyB0BzztG0DyE0B0BtGyE0CzzyDtGzy0FzyzztGyDtAzyzz0F0DtD0Ezy0CyBzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBzyyD%26crEn quarantaineD533988356%26aEn quarantaineDwncy_vit_15_26%26osEn quarantaineDWindows 8.1&p={searchTerms}, [4b2440c44d3e171f53b5c5da4db7bb45], %5 PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\chrome.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [6e010ef6f299e2547a0fd9c855afe917] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\explorer.xxx|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [75faaf55d2b9ec4aafda4160ce36c23e] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\firefox.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [5b14b4507f0cef47b0d94c55d2322cd4] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\iexplore.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [94db7f85b5d672c439507e235ea69b65] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\msiexec.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [b0bf8e76711a2214e4a54a5740c405fb] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\SearchProtectionSetup.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [5817dc287813f2443a4f356cb94b24dc] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\SearchProtectionStub.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [a2cdab59ee9d102644455051996bc838] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\SettingsManagerSetup.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [353a1ce8dcafa690c7c2752c29db4bb5] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\SetupDataMg.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [72fd55af93f850e6e0a900a11aea5ba5] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\SetupDataMngr_iLivid.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [a6c95ca85b30043256333c65976d07f9] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\SetupDataMngr_iMesh.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [b9b6d1339dee49ed63265a47e420cd33] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\software_removal_tool.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [4728eb19f7945dd93356841dfa0a56aa] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\software_reporter_tool.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [7bf4b1532e5d55e1f792d1d01ce8f20e] PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32Ldr|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130703992694178041, En quarantaine, [9dd2a262276411259bef3d64e51f7090] PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, En quarantaine, [c1aedb29a6e5e650e54c663b020232ce] PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, En quarantaine, [beb13dc726650333f33e00a127dd60a0] PUP.Optional.Shopperz.A, HKU\S-1-5-18\SOFTWARE\{1a945540-4e69-4cfb-a200-900b2040e440}|Name, C:\Program Files\shopperz27072015\Wxnuan.exe, En quarantaine, [a5ca7b89117a03336317f8b036cea25e] PUP.Optional.Shopperz.A, HKU\S-1-5-19\SOFTWARE\{1a945540-4e69-4cfb-a200-900b2040e440}|Name, C:\Program Files\shopperz27072015\Wxnuan.exe, En quarantaine, [a4cbaa5a0e7ded49136743657c88bb45] PUP.Optional.Shopperz.A, HKU\S-1-5-20\SOFTWARE\{1a945540-4e69-4cfb-a200-900b2040e440}|Name, C:\Program Files\shopperz27072015\Wxnuan.exe, En quarantaine, [135c758f177486b0a6d4a107f212966a] PUP.Optional.Shopperz.A, HKU\S-1-5-21-2298773659-1734756943-2230792534-1001\SOFTWARE\{1a945540-4e69-4cfb-a200-900b2040e440}|Name, C:\Program Files\shopperz27072015\Wxnuan.exe, En quarantaine, [c4ab0df7ff8c66d0a6d430783bc91ce4] Données du registre: 0 (Aucun élément malveillant détecté) Dossiers: 2 PUP.Optional.Deal4Me.A, C:\Program Files (x86)\DeeAAl4me, En quarantaine, [690647bda9e25cda6edb8415e61ec33d], PUP.Optional.MultiPlug.A, C:\Program Files (x86)\C385AA21-1437776796-E411-AA1F-F0761C384467, En quarantaine, [7af5fd078ffc3bfb1699c5e211f35ca4], Fichiers: 45 PUP.Optional.WebTInst.A, C:\Windows\System32\drivers\Msft_Kernel_webTinstMKTN84_01009.Wdf, Supprimer au redémarrage, , PUP.Optional.ServiceRNDM.A, C:\Program Files (x86)\Testy Option\Testy Option.exe, Supprimer au redémarrage, [9bd4b84cbfcc80b6336080478180c739], PUP.Optional.WProtectManager.A, C:\ProgramData\5WinManPro5\ProtectWindowsManager.exe, En quarantaine, [fe7133d16b20f83e6d5b1b5f37ce55ab], PUP.Optional.WProtectManager.A, C:\ProgramData\9WinManPro9\ProtectWindowsManager.exe, En quarantaine, [0f60887c107b2d09f6d22b4fdd282ad6], PUP.Optional.WProtectManager.A, C:\ProgramData\lWinManProl\ProtectWindowsManager.exe, En quarantaine, [600fe71d7d0e73c3a82028526b9a847c], PUP.Optional.WProtectManager.A, C:\ProgramData\rWinManPror\ProtectWindowsManager.exe, En quarantaine, [a8c7689cd4b7b87ec305d1a95baa817f], PUP.Optional.WProtectManager.A, C:\Users\Elise\AppData\Roaming\ZHP\Quarantine\ProtectWindowsManager.exe, En quarantaine, [94db9b69117a2b0b04c4b3c736cf09f7], PUP.Optional.Nova.A, C:\Users\Elise\AppData\Roaming\ZHP\Quarantine\85d53227-0ebf-47fa-93cc-c02dc13b03d0\36d01b0c-9586-4aba-b777-d20c39edabcb.dll, En quarantaine, [4e21bc488dfee15542fcabb09e63f30d], PUP.Optional.Crossrider, C:\Users\Elise\AppData\Roaming\ZHP\Quarantine\85d53227-0ebf-47fa-93cc-c02dc13b03d0\85d53227-0ebf-47fa-93cc-c02dc13b03d0.dll, En quarantaine, [fc7350b483080e285162892547badf21], PUP.Optional.Nova.A, C:\Users\Elise\AppData\Roaming\ZHP\Quarantine\85d53227-0ebf-47fa-93cc-c02dc13b03d0\bb3d5d90-44d0-40a8-87e1-6457e9bcbf99.dll, En quarantaine, [6d02a064fd8e67cf023c2734cd34c13f], PUP.Optional.Crossrider, C:\Users\Elise\AppData\Roaming\ZHP\Quarantine\85d53227-0ebf-47fa-93cc-c02dc13b03d0\de240657-519a-4edc-ad9d-08128fefeed1.dll, En quarantaine, [8ee1e321ff8ccf6709aa6e4014edf10f], PUP.Optional.Iminent.A, C:\Users\Elise\AppData\Roaming\ZHP\Quarantine\Iminent\Minibar.InternetExplorer.BHOx64.dll, En quarantaine, [29465aaac5c69f97e5685a20b352c739], PUP.Optional.Iminent.A, C:\Users\Elise\AppData\Roaming\ZHP\Quarantine\Iminent\Minibar.InternetExplorer.BHOx86.dll, En quarantaine, [91de82823853ce683c111169ce3728d8], PUP.Optional.SoftwareUpdate.A, C:\Users\Elise\AppData\Roaming\ZHP\Quarantine\Software\Update\SoftwareUpdate.exe, En quarantaine, [3b345da7d5b6dd59c6e41439a1604eb2], Adware.ConvertAd, C:\Program Files (x86)\C385AA21-1437776796-E411-AA1F-F0761C384467\hnsh9550.tmp, En quarantaine, [e8870ff58efdb97d33a62a9faa57a55b], PUP.Optional.Multiplug.A, C:\Program Files (x86)\ProcessFoobar\ProcessFoobar.dll, En quarantaine, [c8a746beaae13ff77dd0fb9904fd49b7], PUP.Optional.Amonentize.A, C:\Users\Elise\AppData\Local\Temp\nspCFBC.tmp, En quarantaine, [680736cee5a622149e12386d59a8d12f], PUP.Optional.Iminent.A, C:\Users\Elise\AppData\Local\Temp\nsrC753.tmp, En quarantaine, [0966897bcbc074c299b4b3c707fe5fa1], PUP.Optional.MyStartSearch.ShrtCln, C:\Users\Elise\AppData\Local\Temp\nsbA091.tmp, En quarantaine, [dc93e123c3c890a6f584186040c55da3], PUP.Optional.IStartSurf.ShrtCln, C:\Users\Elise\AppData\Local\Temp\nsfC2CF.tmp, En quarantaine, [7df2d3310487de58e010fd7afb0a36ca], PUP.Optional.IStartSurf.ShrtCln, C:\Users\Elise\AppData\Local\Temp\nshC937.tmp, En quarantaine, [69063fc5d3b877bfda16a9cedf26629e], PUP.Optional.Iminent.A, C:\Users\Elise\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_118.exe, En quarantaine, [4f2008fc0289e94d004d3248669f768a], PUP.Optional.Tuto4PC.A, C:\Users\Elise\AppData\Local\Temp\is-ODFPO.tmp\gentlemjmp_ieu.exe, En quarantaine, [e8875ea68308270fad067bfe877ea858], PUP.Optional.MyBestOffersToday.A, C:\Users\Elise\AppData\Local\Temp\is-OMH1E.tmp\gentlemjmp_ieu.exe, En quarantaine, [f778ab594744979fa941c68a33ce20e0], PUP.Optional.CheckOffer, C:\Users\Elise\AppData\Local\Temp\nsgF6D7.tmp\nsCBHTML5.dll, En quarantaine, [d19ee024f497c96d24b11592d82953ad], Adware.ConvertAd, C:\Windows\Temp\EE07.tmp.exe, En quarantaine, [5916857f8b00979fdffc02c77d84a65a], Adware.ConvertAd, C:\Windows\Temp\A8CD.tmp.exe, En quarantaine, [0b64e81c9deef145a83367629d64e41c], Adware.ConvertAd, C:\Windows\Temp\857B.tmp.exe, En quarantaine, [e58a758f2764979fa15fe7e35fa26997], Adware.ConvertAd, C:\Windows\Temp\8DE8.tmp.exe, En quarantaine, [f7783aca5d2e3204f8e3c306db261ce4], Adware.ConvertAd, C:\Windows\Temp\9046.tmp.exe, En quarantaine, [b3bc24e0ddae44f247943c8d10f15da3], Adware.ConvertAd, C:\Windows\Temp\5BA9.tmp.exe, En quarantaine, [d39c64a0dead62d4a8339534b948a858], Adware.ConvertAd, C:\Windows\Temp\63B9.tmp.exe, En quarantaine, [83ec26def5968fa74299725722dfc838], Adware.ConvertAd, C:\Windows\Temp\6E61.tmp.exe, En quarantaine, [393642c2a1ea1e18e0fbefda1ee337c9], Adware.ConvertAd, C:\Windows\Temp\B5A7.tmp.exe, En quarantaine, [6e0137cd7f0c1125f2e9d9f02ed333cd], Adware.ConvertAd, C:\Windows\Temp\9812.tmp.exe, En quarantaine, [83ec25df8b0089ade8f3caff2ed307f9], Adware.ConvertAd, C:\Windows\Temp\FA9A.tmp.exe, En quarantaine, [fa75e3215932e1555586e8e1926ff30d], PUP.Optional.MultiPlug.A, C:\Windows\Temp\tmpsfd4so\tujXIsVNzy5Xvb.dll, En quarantaine, [b5ba4fb512799f971ff4aa15db26ca36], PUP.Optional.MultiPlug.A, C:\Windows\Temp\tmpsfd4so\tujXIsVNzy5Xvb.x64.dll, En quarantaine, [59168e76ff8c40f67c979d22e0217888], PUP.Optional.Deal4Me.A, C:\Program Files (x86)\DeeAAl4me\tujXIsVNzy5Xvb.tlb, En quarantaine, [690647bda9e25cda6edb8415e61ec33d], PUP.Optional.Deal4Me.A, C:\Program Files (x86)\DeeAAl4me\tujXIsVNzy5Xvb.dat, En quarantaine, [690647bda9e25cda6edb8415e61ec33d], PUP.Optional.MultiPlug.A, C:\Program Files (x86)\C385AA21-1437776796-E411-AA1F-F0761C384467\hnsh9550.tmp, En quarantaine, [7af5fd078ffc3bfb1699c5e211f35ca4], PUP.Optional.MultiPlug.A, C:\Program Files (x86)\C385AA21-1437776796-E411-AA1F-F0761C384467\knsg1067.tmp, En quarantaine, [7af5fd078ffc3bfb1699c5e211f35ca4], PUP.Optional.MultiPlug.A, C:\Program Files (x86)\C385AA21-1437776796-E411-AA1F-F0761C384467\knssF05B.tmp, En quarantaine, [7af5fd078ffc3bfb1699c5e211f35ca4], PUP.Optional.MultiPlug.A, C:\Program Files (x86)\C385AA21-1437776796-E411-AA1F-F0761C384467\Uninstall.exe, En quarantaine, [7af5fd078ffc3bfb1699c5e211f35ca4], PUP.Optional.MultiPlug.A, C:\Program Files (x86)\C385AA21-1437776796-E411-AA1F-F0761C384467\vnsx3C45.tmp, En quarantaine, [7af5fd078ffc3bfb1699c5e211f35ca4], Secteurs physiques: 0 (Aucun élément malveillant détecté) (end)