Malwarebytes Anti-Malware
http://www.malwarebytes.org
Date de l'examen: 19/07/2014
Heure de l'examen: 10:32:04
Fichier journal:
Administrateur: Oui
Version: 2.00.2.1012
Base de données Malveillants: v2014.07.19.02
Base de données Rootkits: v2014.07.17.01
Licence: Gratuite
Protection contre les malveillants: Désactivé(e)
Protection contre les sites Web malveillants: Désactivé(e)
Self-protection: Désactivé(e)
Système d'exploitation: Windows 7 Service Pack 1
Processeur: x64
Système de fichiers: NTFS
Utilisateur: podams
Type d'examen: Examen "Menaces"
Résultat: Terminé
Objets analysés: 326707
Temps écoulé: 24 min, 26 sec
Mémoire: Activé(e)
Démarrage: Activé(e)
Système de fichiers: Activé(e)
Archives: Activé(e)
Rootkits: Désactivé(e)
Heuristics: Activé(e)
PUP: Activé(e)
PUM: Activé(e)
Processus: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Clés du Registre: 7
PUP.Optional.Windealist.A, HKU\S-1-5-21-2910980931-1586082648-3272160621-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{B8F10001-9552-4F40-8F61-6765CD22DD9E}, Mis en quarantaine, [015de8b9b2c994a24e05bdd52dd5ad53],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{CE681A67-9477-CBE6-EB9D-FE534875F98D}, Mis en quarantaine, [500e0899027955e1a566a8ae2fd3f10f],
PUP.Optional.CouponDownloader.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Coupon Downloader, Mis en quarantaine, [441ad8c99be074c2ff68844f28da04fc],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-9.1, Mis en quarantaine, [a4ba8a173d3ede5821cc4e8eda28fe02],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-V1.1, Mis en quarantaine, [b8a65e4386f503331d496079ab5748b8],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
Valeurs du Registre: 2
PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|fst_fr_177, Mis en quarantaine, [322c8a17007bc86e9ab722b4d42ed62a],
PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|fst_fr_174, Mis en quarantaine, [a9b53071384359dd411012c4ee14d32d],
Données du Registre: 0
(No malicious items detected)
Dossiers: 1
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
Fichiers: 46
Adware.Agent, C:\ProgramData\InstallMate\{1279DF45-2464-42ED-A006-6C46C99AFDB3}\Custom.dll, Mis en quarantaine, [f16d7130671442f419d2d185c33e16ea],
Trojan.Ransom.ED, C:\Users\podams\AppData\Roaming\.#\omgvzgf.exe, Supprimé-au-redémarrage, [342a8e1344374beb0681ddbc877afb05],
PUP.Optional.AppsInstaller, C:\FLV_Media_Player.exe, Mis en quarantaine, [5608cfd25427f640dc9fe7472fd52ed2],
PUP.Optional.ZombieAlert.A, C:\Windows\SysWOW64\ZombieAlert.A222801BB6B4.2.6.80.dll, Mis en quarantaine, [342abfe2accf5adcd0081776a85c20e0],
PUP.Optional.CouponDownloader.A, C:\Users\podams\AppData\Local\Temp\nsa94B2.tmp.exe, Mis en quarantaine, [f36b732edf9caa8cbe9b5ae98b7548b8],
PUP.Optional.InstallCore.A, C:\Users\podams\AppData\Local\Temp\nsl8955.tmp, Mis en quarantaine, [fb632a77d5a642f4a4f90277f908f10f],
Trojan.Agent.SCT, C:\Users\podams\AppData\Local\Temp\setup_293.exe, Mis en quarantaine, [392559488af1b77fbf86bddaa16059a7],
PUP.Optional.SilentInstaller.A, C:\Users\podams\AppData\Local\Temp\setup_ra.exe, Mis en quarantaine, [96c8bde4423984b2a2ae5eee32d06c94],
PUP.Optional.SweetIM, C:\Users\podams\AppData\Local\Temp\Shortcut_SweetImSetup(1).exe, Mis en quarantaine, [2638bfe23843b383a55d00cdb2524fb1],
PUP.Optional.SearchHijacker.A, C:\Users\podams\AppData\Local\Temp\smt_omiga-plus.exe, Mis en quarantaine, [d18d663b0279181e1d448c0ac93812ee],
PUP.Optional.InstallCore.A, C:\Users\podams\AppData\Local\Temp\ICReinstall_nsl8955.tmp, Mis en quarantaine, [134be8b990ebd561f7a60673f40d7789],
Adware.MovieMode, C:\Users\podams\AppData\Local\Temp\Setup.exe, Mis en quarantaine, [421cedb41b600036c6ec2d3d719060a0],
PUP.Optional.BubbleDock.A, C:\Users\podams\AppData\Local\Temp\Install_BubbleDock.exe, Mis en quarantaine, [70eedac72b50a09684f5c18178896898],
PUP.Optional.Trolotunt.A, C:\Users\podams\AppData\Local\Temp\trolatuntSetup.exe, Mis en quarantaine, [cc92a10048331125a58a48504db7cf31],
PUP.Optional.SweetIM, C:\Users\podams\AppData\Local\Temp\mgsqlite3.7z, Mis en quarantaine, [69f561406615f93d2bd7428b689c738d],
PUP.Optional.SweetIM, C:\Users\podams\AppData\Local\Temp\mgsqlite3.dll, Mis en quarantaine, [c5995e430d6e10267191804dca3a30d0],
PUP.Optional.BubbleDock.A, C:\Users\podams\AppData\Local\Temp\472014211735\Uninstall Bubble Dock.exe, Mis en quarantaine, [8cd231702a5137ffcfaa77cb8c753cc4],
PUP.Optional.SkyTech.A, C:\Users\podams\AppData\Local\Temp\49535465\49535465.zipDir\alilog.dll, Mis en quarantaine, [94ca079a1c5ff73f141b052d1ee28b75],
PUP.Optional.V9.A, C:\Users\podams\AppData\Local\Temp\49535465\49535465.zipDir\qSE.exe, Mis en quarantaine, [eb73aff26e0d2c0a538adb6d0df314ec],
PUP.Optional.Skytech.A, C:\Users\podams\AppData\Local\Temp\49535465\49535465.zipDir\UninstallManager.exe, Mis en quarantaine, [63fb3869d7a4b3830888dcb1bb4626da],
PUP.Optional.IePluginService.A, C:\Users\podams\AppData\Local\Temp\49535465\49535465.zipDir\tmp\SupTab.exe, Mis en quarantaine, [a9b51b86b5c689ad4ff45707c43d5ea2],
PUP.Optional.WpManager, C:\Users\podams\AppData\Local\Temp\49535465\49535465.zipDir\tmp\wpm.exe, Mis en quarantaine, [104e39681e5d0b2baf1473f552af4fb1],
PUP.Optional.Linkey.A, C:\Users\podams\AppData\Local\Temp\is45637729\108033_stp\SettingsManagerSetup.exe, Mis en quarantaine, [61fdc3dea2d9ed495732eaa49a67d32d],
PUP.Optional.CouponDownloader.A, C:\Users\podams\AppData\Local\Temp\is45637729\108134_stp\coupondownloader.exe, Mis en quarantaine, [520c30714c2f003643cf2a68689c53ad],
PUP.Optional.MySearchDial.A, C:\Users\podams\AppData\Local\Temp\is49861164\mysearchdial.dll, Mis en quarantaine, [124c2b761764df57fdedb4a67d84a15f],
PUP.Optional.SweetIM, C:\Users\podams\AppData\Local\Temp\{F62A7363-2441-40A2-B53F-E3B284895254}\{F5A88299-C9AF-44D7-9F3D-84589F1DB30F}\BundleSweetIMSetup.exe, Mis en quarantaine, [1945455c6e0dc76ff60c01cc28dcbe42],
PUP.Optional.FreeSoftToday.A, C:\Users\podams\AppData\Local\Temp\n1052\fst_fr_0805-58f0869e.exe, Mis en quarantaine, [b4aa8021710a7bbb04867d12669ba45c],
PUP.Optional.BundleInstaller.A, C:\Users\podams\AppData\Local\Temp\n1052\s1052.exe, Mis en quarantaine, [4e107928f18a79bd04e7e35ec9376d93],
PUP.Optional.MultiPlug, C:\Users\podams\AppData\Local\Temp\98523240\C9Uv5VvT2425i.exe, Mis en quarantaine, [1648f6ab502bd95d05427c1f976a03fd],
PUP.Optional.Preload, C:\Users\podams\AppData\Local\Temp\98523240\jc5gDwtYrtnCG48.exe, Mis en quarantaine, [540a7b26324982b463e527741ee3ff01],
PUP.Optional.Preload, C:\Users\podams\AppData\Local\Temp\98523240\Q21432.exe, Mis en quarantaine, [3f1fdec3e19ac076ed57d6c58f72847c],
PUP.Optional.Somoto.A, C:\Users\podams\Downloads\StreamingLiveHD_downloader_by_StreamingLiveHD.exe, Mis en quarantaine, [36284f524f2c072fea3886b251af25db],
PUP.Optional.LiveLyrics.A, C:\Users\podams\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.livelyrics00.live-lyrics.com_0.localstorage, Mis en quarantaine, [2d314c5526550234a4e926abbc463ac6],
PUP.Optional.LiveLyrics.A, C:\Users\podams\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.livelyrics00.live-lyrics.com_0.localstorage-journal, Mis en quarantaine, [65f9623f017a20163a539140936fea16],
Exploit.Drop.GS, C:\Users\podams\AppData\Local\Temp\fvJcrgR.exe, Mis en quarantaine, [d886326f4833102608066b9d56adf907],
Exploit.Drop.GS, C:\Users\podams\AppData\Local\Temp\fvJcrgR0.exe, Mis en quarantaine, [2d31554c22592115b55a0bfdbf44b050],
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330\GoogleCrashHandler.exe, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330\GoogleUpdate.exe, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330\GoogleUpdateBroker.exe, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330\GoogleUpdateHelper.msi, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330\GoogleUpdateOnDemand.exe, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330\goopdate.dll, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330\goopdateres_en.dll, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330\npGoogleUpdate4.dll, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330\psmachine.dll, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
PUP.Optional.GlobalUpdate.A, C:\Users\podams\AppData\Local\Temp\comh.78330\psuser.dll, Mis en quarantaine, [ee705e430c6fc3739795d2eb2bd7c53b],
Secteurs physiques: 0
(No malicious items detected)
(end)