Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)
SweetPacks Mahjong est un adware (logiciel publicitaire), qui affiche des publicités intempestives indépendantes des sites visités.
- S'installe en tant que programme, à l'insu de l'utilisateur ou parce qu'il n'a pas décoché les sponsors proposés lors de l'installation d'un logiciel gratuit légitime
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FMahjongSweetIM%2Fwarning4.png&key=1397113610e2e8c0d4808190a86b173d8534cfa5fd74a2fa01f3937540c0bc52)
- SweetPacks Mahjong affiche ces différentes fenêtres pendant l'installation, qu'il faut décliner en décochant le sponsor ou par Decline
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FMahjongSweetIM%2Fmain.png&key=c1c285e0096d2eacdbdd9acd64be70a769baefecd8a9ced72c6111ba7417baac)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FMahjongSweetIM%2Fwarning1.png&key=45df304811672472b015144dda5be28a376871d9c90b060cd86f9af65f30976f)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FMahjongSweetIM%2Fwarning2.png&key=84fdbe20ed54337aab2b72a02c86edf1cac9579461e52d4604f97df868a31ce8)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FMahjongSweetIM%2Fwarning3.png&key=f04a7a9f705ce9e7ebfa5d8e68a9e530e2efc7362964e2df8469e67d78a9b386)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FMahjongSweetIM%2Fwarning5.png&key=ab89ef5b30fcc3c3afd07663eb4954cd8acffdd4e81d764ca316308e159a8553)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FMahjongSweetIM%2Fwarning6.png&key=312db8b4bf594762c7564eaa1d437501ce424751f83544ad9f9b9c181df689e4)
- SweetPacks Mahjong crée des raccourcis sur le Bureau et et dans la Barre des tâches
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FMahjongSweetIM%2Ficons.png&key=dcd1c97b3c01eb0081cbe346f94e71c888a82078813f7774fe4f7942232d0302)
**********
Détection de SweetPacks Mahjong dans des rapports FRST :
Free Ride Games Player (x32 Version: - Exent Technologies Ltd) Hidden
Mahjong: Mysteries of the Past Bundle by SweetPacks (HKLM-x32\...\Mahjong: Mysteries of the Past Bundle by SweetPacks) (Version: 1.0.0.0 - SweetPacks LTD)
SweetPacks Updater (x32 Version: 4.0.1.0 - ) Hidden
ShortcutWithArgument: C:\Users\Nom_Utilisateur\Desktop\Play Mahjong Mysteries of the Past.lnk -> C:\Remote Programs\Mahjong Mysteries of the Past\GPlrLanc.exe (Exent Technologies Ltd.) -> -LOpCode 1 -shortcut hxxp://www.freeridegames.com/main/shortcut.jsp?theme=Home&AppId=765950&RunIndex=1&PrvId=143&AcID=&OpenShInIE=0&PrvDir=Default
ShortcutWithArgument: C:\Users\Nom_Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Ride Games\Mahjong Mysteries of the Past\Play Mahjong Mysteries of the Past.lnk -> C:\Remote Programs\Mahjong Mysteries of the Past\GPlrLanc.exe (Exent Technologies Ltd.) -> -LOpCode 1 -shortcut hxxp://www.freeridegames.com/main/shortcut.jsp?theme=Home&AppId=765950&RunIndex=1&PrvId=143&AcID=&OpenShInIE=0&PrvDir=Default
FirewallRules: [{B37EBFE3-95F2-470D-AE54-C0AACC7AA370}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{B1F8A31A-9FA7-4DD4-BDAC-B8129A942394}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{2F336BDD-D0F6-410B-AB92-93C4D15A381F}] => (Allow) C:\Windows\SysWOW64\ARFC\wrtc.exe
FirewallRules: [{F9D455C7-7A4D-4A5B-8CBB-7E7C63DD2997}] => (Allow) C:\Windows\SysWOW64\ARFC\wrtc.exe
() C:\Windows\System32\dmwu.exe
(Exent Technologies Ltd.) C:\Program Files (x86)\Free Ride Games\GPlayer.exe
HKU\S-1-5-19\...\Run: [Exetender] => C:\Program Files (x86)\Free Ride Games\GPlayer.exe [4932288 AAAA-MM-JJ] (Exent Technologies Ltd.)
HKU\S-1-5-20\...\Run: [Exetender] => C:\Program Files (x86)\Free Ride Games\GPlayer.exe [4932288 AAAA-MM-JJ] (Exent Technologies Ltd.)
HKCU\...\Run: [Exetender] => C:\Program Files (x86)\Free Ride Games\GPlayer.exe [4932288 AAAA-MM-JJ] (Exent Technologies Ltd.)
HKU\S-1-5-18\...\Run: [Exetender] => C:\Program Files (x86)\Free Ride Games\GPlayer.exe [4932288 AAAA-MM-JJ] (Exent Technologies Ltd.)
FF DefaultSearchEngine: SweetIM search
FF DefaultSearchUrl:
FF SelectedSearchEngine: SweetIM search
FF Homepage: hxxp://home.sweetim.com/?crg=3.49010003&ptr=100&st=12&barid={8C2FBFC5-23D7-11E6-9FA8-08002796C23D}
FF Keyword.URL: hxxp://search.sweetim.com/search.asp?src=2&ptr=100&barid={8C2FBFC5-23D7-11E6-9FA8-08002796C23D}&q=
FF Plugin-x32: @exent.com/npExentCtl,version=7.0.0.0 -> C:\Program Files (x86)\Free Ride Games\npExentCtl.dll [2009-12-27] (Exent Technologies Ltd.)
FF Plugin-x32: www.exent.com/GameTreatWidget -> C:\Program Files (x86)\Free Ride Games\NPGameTreatPlugin.dll [No File]
FF SearchPlugin: C:\Users\Nom_Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins\SweetIM Search.xml [AAAA-MM-JJ]
FF SearchPlugin: C:\Users\Nom_Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins\sweetim.xml [AAAA-MM-JJ]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [AAAA-MM-JJ]
R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1277744 AAAA-MM-JJ] ()
R2 X5XSEx_Pr143; C:\Program Files (x86)\Free Ride Games\X5XSEx_Pr143.Sys [56584 AAAA-MM-JJ] (Exent Technologies Ltd.)
U3 X5Ex_Pr143; C:\Program Files (x86)\Free Ride Games\X5Ex_Pr143.Sys [612104 AAAA-MM-JJ] (Exent Technologies Ltd.)
C:\Users\Nom_Utilisateur\Desktop\Play Free Games.lnk
C:\Users\Nom_Utilisateur\Desktop\More FREE games.lnk
C:\Users\Nom_Utilisateur\Desktop\Play Mahjong Mysteries of the Past.lnk
C:\Users\Nom_Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Ride Games
C:\Program Files (x86)\Free Ride Games
C:\Users\Public\Desktop\Play Free Games.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Free Ride Games.lnk
C:\Users\Public\Desktop\More FREE games.lnk
C:\Windows\GPlrLanc.dat
C:\ProgramData\Free Ride Games
(Exent Technologies Ltd.) C:\Windows\ExentInfo.exe
C:\Windows\SysWOW64\WNLT
C:\Windows\SysWOW64\mjcm
C:\Windows\SysWOW64\jmdp
C:\Windows\SysWOW64\ARFC
C:\Windows\system32\tprb
C:\Program Files (x86)\sweetpacks bundle uninstaller
C:\Windows\system32\dmwu.exe
(IncrediMail, Ltd.) C:\Windows\system32\ImHttpComm.dll
**********
Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable).
PUP.Optional.SweetIM
PUP.Optional.SweetPacks
PUP.Optional.Perion
PUP.Optional.InstallBrain
Adware.InstallBrain
Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)
Source : Removal instructions for SweetPacks Mahjong de Metallica - Malwarebytes Forums (https://forums.malwarebytes.org/topic/183662-removal-instructions-for-sweetpacks-mahjong/)
Toujours infecté ? Une question avant de faire des manipulations ?
Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/ en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/