rapport malaware:
Malwarebytes Anti-Malware
www.malwarebytes.orgDate de l'examen: 28/12/2014
Heure de l'examen: 17:05:53
Fichier journal: vv.txt
Administrateur: Oui
Version: 2.00.4.1028
Base de données Malveillants: v2014.12.28.07
Base de données Rootkits: v2014.12.23.02
Licence: Premium
Protection contre les malveillants: Activé(e)
Protection contre les sites Web malveillants: Activé(e)
Auto-protection: Activé(e)
Système d'exploitation: Windows 8.1
Processeur: x64
Système de fichiers: NTFS
Utilisateur: stephany
Type d'examen: Examen "Menaces"
Résultat: Terminé
Objets analysés: 361021
Temps écoulé: 38 min, 52 sec
Mémoire: Activé(e)
Démarrage: Activé(e)
Système de fichiers: Activé(e)
Archives: Activé(e)
Rootkits: Activé(e)
Heuristique: Activé(e)
PUP: Avertir
PUM: Activé(e)
Processus: 0
(Aucun élément malicieux detecté)
Modules: 0
(Aucun élément malicieux detecté)
Clés du Registre: 6
PUP.Optional.Vosteran, HKLM\SOFTWARE\CLASSES\APPID\{4CB3598A-82E8-4D1F-983F-061238AE696E}, , [e262d88ea5d726107d0366707a88d030],
PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{4CB3598A-82E8-4D1F-983F-061238AE696E}, , [e262d88ea5d726107d0366707a88d030],
PUP.Optional.InstallCore.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLCORE\WSE_Vosteran, , [94b0d294136950e68df376f3d42faf51],
PUP.Optional.Vosteran.A, HKU\S-1-5-21-2344320175-4189460588-1261973789-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\wse_vosteran, , [76ce89dd19637bbbb7e0d40b0cf8f010],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2344320175-4189460588-1261973789-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [a2a290d697e592a4ae06138d877c7b85],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2344320175-4189460588-1261973789-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, , [89bb6006146842f4d0ffd7df70948a76],
Valeurs du Registre: 2
PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Vosteran\\, , [9aaacc9a82fa181e323236ab06fecf31]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2344320175-4189460588-1261973789-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0Z1B1L2Z1S, , [89bb6006146842f4d0ffd7df70948a76]
Données du Registre: 1
PUP.Optional.Vosteran.A, HKU\S-1-5-21-2344320175-4189460588-1261973789-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page,
http://Vosteran.com/?f=1&a=vst_ir_14_52 ... 239337&ir=, Bon: (
www.google.com), Mauvais: (
http://Vosteran.com/?f=1&a=vst_ir_14_52 ... 239337&ir=),,[3311a2c4522a9e98b20c94eddb2aea16]
Dossiers: 5
PUP.Optional.Vosteran.A, C:\Users\stephany\AppData\Roaming\WSE_Vosteran, , [c480075fde9ef442c80ded69d82b03fd],
PUP.Optional.Vosteran.A, C:\Users\stephany\AppData\Roaming\WSE_Vosteran\icons_3.6.15.3, , [c480075fde9ef442c80ded69d82b03fd],
PUP.Optional.Vosteran.A, C:\Users\stephany\AppData\Roaming\WSE_Vosteran\UpdateProc, , [c480075fde9ef442c80ded69d82b03fd],
PUP.Optional.Vosteran.A, C:\Program Files (x86)\WSE_Vosteran, , [94b0fc6a9fdd1e184d8adf7772919d63],
PUP.Optional.Vosteran.A, C:\Program Files (x86)\WSE_Vosteran\bh, , [94b0fc6a9fdd1e184d8adf7772919d63],
Fichiers: 34
PUP.Optional.Vosteran.A, C:\Windows\Tasks\WSE_Vosteran.job, , [271d392d126ad462b3e12ab5996b7b85],
PUP.Optional.Vosteran.A, C:\Windows\System32\Tasks\WSE_Vosteran, , [5ce84b1b09733600b9dc36a97f851ae6],
PUP.Optional.Vosteran.A, C:\Users\stephany\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat, , [c480075fde9ef442c80ded69d82b03fd],
PUP.Optional.Vosteran.A, C:\Users\stephany\AppData\Roaming\WSE_Vosteran\UpdateProc\config.dat, , [c480075fde9ef442c80ded69d82b03fd],
PUP.Optional.Vosteran.A, C:\Program Files (x86)\WSE_Vosteran\astcnfg.dat, , [94b0fc6a9fdd1e184d8adf7772919d63],
PUP.Optional.Vosteran.A, C:\Program Files (x86)\WSE_Vosteran\FavIcon.ico, , [94b0fc6a9fdd1e184d8adf7772919d63],
PUP.Optional.Vosteran.A, C:\Program Files (x86)\WSE_Vosteran\Sqlite3.dll, , [94b0fc6a9fdd1e184d8adf7772919d63],
PUP.Optional.Vosteran.A, C:\Program Files (x86)\WSE_Vosteran\uninst.dat, , [94b0fc6a9fdd1e184d8adf7772919d63],
PUP.Optional.Vosteran.A, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\prefs.js, Bon: (), Mauvais: (user_pref("browser.startup.homepage", "http://Vosteran.com/?f=1&a=vst_ir_14_52_ff&cd=2XzuyEtN2Y1L1QzuyE0CyBtB0Bzy0AyCzytDtDtDzytA0BtCtN0D0Tzu0StCtDzytBtN1L2XzutAtFyCtFtCyDtFtAtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0Fzy0CyCzzzzyEtGtDtDtAyDtG0FyCtB0FtG0B0F0EzytGtB0EtA0AyCzytDtB0C0A0CtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0EtB0B0AtCtD0FtGzy0C0A0FtGyEyByBtCtG0A0DyC0BtGyCzyyB0Bzz0BtByBtAtCyB0F2Q&cr=558239337&ir=");), ,[182c0c5a3d3f26104ae100bbbc49966a]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (user_pref("extensions.srchvstrn.hmpg", true);), ,[f1534a1c2854e353053ff1c5b550e11f]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (sions.srchvstrn.hmpg", true);
user_pref("extensions.srchvstrn.hmpgUrl", "http://Vosteran.com/?f=1&a=vst_ir_14_52_ff&cd=2XzuyEtN2Y1L1QzuyE0CyBtB0Bzy0AyCzytDtDtDzytA0BtCtN0D0Tzu0StCtDzytBtN1L2XzutAtFyCtFtCyDtFtAtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0Fzy0CyCzzzzyEtGtDtDtAyDtG0FyCtB0FtG0B0F0EzytGtB0EtA0AyCzytDtB0C0A0CtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0EtB0B0AtCtD0FtGzy0C0A0FtGyEyByBtCtG0A0DyC0BtGyCzyyB0Bzz0BtBy), ,[92b23630cab2be784400dfd7c342fd03]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (zy0C0A0FtGyEyByBtCtG0A0DyC0BtGyCzyyB0Bzz0BtByBtAt), ,[172d82e494e8f73f2f15a01660a5758b]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (s.srchvstrn.hmpg", true);
user_pref("extensions.srchvst), ,[76cee284f884989e380c05b10cf90bf5]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (strn.hmpg", true);
user_pref("extensions.srchv), ,[b68e2a3c413b280e68dc03b372936997]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (ons.srchvstrn.hmpg", true);
user_pref("extension), ,[3d07273f07759f97c87c84323cc910f0]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (s.srchvstrn.hmpg", true);
user_pref("extensions.srchvstrn.hmpgUrl", "http://Vosteran.com/?f=1&a=vst_ir_14_52_ff&cd=2XzuyEtN2Y1L1QzuyE0CyBtB0Bzy0AyCzytDtDtDzytA0BtCtN0D0Tzu0StCtDzytBtN1L2XzutAtFyCtFtCyDtFtAtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0Fzy0CyCzzzzyEtGtDtDtAyDtG0FyCtB0FtG0B0F0EzytGtB0EtA0AyCzytDtB0C0A0CtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0EtB0B0AtCtD0FtGzy0C0A0FtGyEyByBtCtG0A0DyC0BtGyCzyyB0Bzz0BtByBtAtCy), ,[182c9ccacbb1d6600a3a9f173bcac23e]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (0C0A0FtGyEyByBtCtG0A0DyC0BtGyCzyyB0Bzz0BtByBtAtCyB0F2Q&cr=558239337&ir=");
user_pref("extensions.srchvstrn.dfltSrch", true);
user_pref("extensions.srchvstrn.srchPrvdr", "Vosteran");
user_pref("extensions.srchvstrn.dnsErr", true);
user_pref("extensions.srchvstrn_i.newTab", true);
user_pref("extensions.srchvstrn.newTabUrl", "http://Vosteran.com/?f=2&a=vst_ir_14_52_ff&cd=2XzuyEtN2Y1L1QzuyE0CyBtB0Bzy0AyCzytDtDtDzytA0BtC), ,[ed570f57611be25451f30aac30d5fd03]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (FtGyEyByBtCtG0A0DyC0BtGyCzyyB0Bzz0BtByBtAtCyB0F2Q&cr=5582), ,[68dc45215824fb3b1a2a6c4a58adca36]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (trn.hmpg", true);
user_pref("extensions.srchvstrn.h), ,[c18340261b614de9e75d81351aeb946c]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (rchvstrn.hmpg", true);
user_pref("extensio), ,[6fd563032b5145f192b2bafc36cf3ac6]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (ensions.srchvstrn.hmpg", true);
user_pref("), ,[7cc8e4828af26fc77bc97541689dd030]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (nsions.srchvstrn.hmpg", true);
user_pref("extensions.s), ,[261ea6c0552736002c18e5d193720cf4]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (vstrn.hmpg", true);
user_pref("extensions.srchvstrn.hmpgU), ,[f64ea0c6a4d85dd9cc780ea8dc290000]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (rn.hmpg", true);
user_pref("extensions.srchvstrn.hmp), ,[da6afd69671524127dc7af07eb1aa759]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (chvstrn.hmpg", true);
user_pref("extensions.srchvstrn.hmp), ,[1d27c79f5329330345ff6c4a59ac38c8]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (rn.hmpg", true);
user_pref("extensions.srchvstrn.hm), ,[99abc99d4c3057dfcc78278f768fb14f]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (rchvstrn.hmpg", true);
user_pref("extensions), ,[89bb8adcd7a5b68081c345712ed7718f]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (sions.srchvstrn.hmpg", true);
user_pref("extensions.sr), ,[89bb1d49126ac472ab999323e3229d63]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (vstrn.hmpg", true);
user_pref("extensions.src), ,[90b41f470d6f25112d17c3f354b15ca4]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (ions.srchvstrn.hmpg", true);
user_pref("extensions.srchvstrn.hmpgUrl", "http://Vo), ,[99abef77f4883df9ec5807af828323dd]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (ref("extensions.srchvstrn.hmpgUrl", "http://Voste), ,[4ff56df955271d191e26cfe747be12ee]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (s.srchvstrn.hmpg", true);
user_pref("extensions.s), ,[c87c075fe29abf77ed5763531ee77e82]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (.srchvstrn.hmpg", true);
user_pref("extensions.srchvstrn.hmpgUrl", "http://Vosteran.com/?f=1&a=vst_ir_14_52_ff&cd=2XzuyEtN2Y1L1QzuyE0CyBtB0Bzy0AyCzytDtDtDzytA0BtCtN0D0Tzu0StCtDzytBtN1L2XzutAtFyCtFtCyDtFtAtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0Fzy0CyCzzzzyEtGtDtDtAyDtG0FyCtB0FtG0B0F0EzytGtB0EtA0AyCzytDtB0C0A0CtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S), ,[1b297bebdca0ef470b39199dc3420000]
PUP.Optional.Vosteran, C:\Users\stephany\AppData\Roaming\Mozilla\Firefox\Profiles\43dhnoxs.default\user.js, Bon: (), Mauvais: (tB0EtA0AyCzytDtB0C0A0CtB2QtN1M1F1B2Z1V1N), ,[cb79d29499e332041f258234778e17e9]
Secteurs physiques: 0
(Aucun élément malicieux detecté)
(end)