Security-X

Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le juin 07, 2016, 18:00:09

Titre: YesSearches
Posté par: chantal11 le juin 07, 2016, 18:00:09
Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)

YesSearches est un Browser Hijacker (pirate de navigateur) qui modifie les paramètres du navigateur (page d’accueil , page de recherche, ....) afin de forcer la consultation du site ciblé et affiche aussi des publicités.
Celui-ci crée un nouveau profil Firefox.


(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FYesSearches%2Fwarning4.png&key=a8e29650e58258c3e54aa717f1d10d2ebd90994519ee228df1c2657b5a5f62d8)

(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FYesSearches%2Fwarning1.png&key=7d6634cd0f81f25febd2b245d0e571cd93f1793f57c621ea65d05b06a4ce2d66)

(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FYesSearches%2Fwarning5.png&key=ccd6cb0fc4958a39c35afc0b5877b443e3866589a75817f3a25facae93ea94de)


(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FYesSearches%2Fwarning6.png&key=9f98591925e85ad48e0362b98fe464a65e4d7ae1df44bb7076d2ff53d2106f00)



**********

Détection de YesSearches dans des rapports FRST :

Citer
yessearches - Uninstall (HKLM-x32\...\Uninstall - obs) (Version:  - )
Task: {88210FD6-28C7-4AA9-BC2C-5E3154354AC9} - System32\Tasks\Jejochclipasp Schedule => C:\Program Files (x86)\Jejochclipasp\jjcscheduletask.exe [AAAA-MM-JJ] ()
ShortcutWithArgument: C:\Users\{username}\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yessearches.com/?ts=AHEqAH0oBXYpBU..&v=20160415&uid=CB75DF05542D4707119BC449A5FA9A4A&ptid=obs&mode=scrp
ShortcutWithArgument: C:\Users\Nom_Utilisateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yessearches.com/?ts=AHEqAH0oBXYpBU..&v=20160415&uid=CB75DF05542D4707119BC449A5FA9A4A&ptid=obs&mode=scrp
ShortcutWithArgument: C:\Users\Nom_Utilisateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yessearches.com/?ts=AHEqAH0oBXYpBU..&v=20160415&uid=CB75DF05542D4707119BC449A5FA9A4A&ptid=obs&mode=scrp
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yessearches.com/?ts=AHEqAH0oBXYpBU..&v=20160415&uid=CB75DF05542D4707119BC449A5FA9A4A&ptid=obs&mode=scrp
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yessearches.com/?ts=AHEqAH0oBXYpBU..&v=20160415&uid=CB75DF05542D4707119BC449A5FA9A4A&ptid=obs&mode=scrp
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yessearches.com/?ts=AHEqAH0oBXYpBU..&v=20160415&uid=CB75DF05542D4707119BC449A5FA9A4A&ptid=obs&mode=scrp
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yessearches.com/?ts=AHEqAH0oBXYpBU..&v=20160415&uid=CB75DF05542D4707119BC449A5FA9A4A&ptid=obs&mode=scrp

FF ProfilePath: C:\Users\Nom_Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
 FF NewTab: hxxp://www.yessearches.com/?ts=AHEqAH0oBXYpBU..&v=20160415&uid=CB75DF05542D4707119BC449A5FA9A4A&ptid=obs&mode=ffseng
 FF DefaultSearchEngine: yessearches
 FF SelectedSearchEngine: yessearches
 FF Homepage: hxxp://www.yessearches.com/?ts=AHEqAH0oBXYpBU..&v=20160415&uid=CB75DF05542D4707119BC449A5FA9A4A&ptid=obs&mode=ffseng
 FF SearchPlugin: C:\Users\Nom_Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml [AAAA-MM-JJ]
 FF Extension: GsearchFinder - C:\Users\Nom_Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi [AAAA-MM-JJ]
 CHR HomePage: Default -> hxxp://www.yessearches.com/?mode=nnnb&ptid=obs&uid=CB75DF05542D4707119BC449A5FA9A4A&v=20160415&ts=AHEqAH0oBXYpBU..
 CHR StartupUrls: Default -> "hxxp://www.yessearches.com/?mode=nnnb&ptid=obs&uid=CB75DF05542D4707119BC449A5FA9A4A&v=20160415&ts=AHEqAH0oBXYpBU.."
 CHR DefaultSearchURL: Default -> hxxp://www.yessearches.com/chrome.php?q={searchTerms}&ts=AHEqAH0oBXYpBU..&v=20160415&uid=CB75DF05542D4707119BC449A5FA9A4A&ptid=obs&mode=nnnb
 CHR DefaultSearchKeyword: Default -> yessearches
 S2 BugreportW; C:\Program Files (x86)\yesbnd\mbat.exe [988176 AAAA-MM-JJ] ()
 S2 jjcscheduleservice; C:\Program Files (x86)\Jejochclipasp\jjcscheduleservice.exe [310768 AAAA-MM-JJ] ()
 C:\Users\Nom_Utilisateur\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
 C:\Windows\System32\Tasks\Jejochclipasp Schedule
 C:\Users\Public\Documents\dmp
 C:\Program Files (x86)\yesbnd
 C:\Program Files (x86)\Jejochclipasp



**********

Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable)

Citer
PUP.Optional.YesSearches
PUP.Optional.CrossAd.Gen
PUP.Optional.FakeFFProfile


Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)


Source : Removal instructions for YesSearches de Metallica - Malwarebytes Forums (https://forums.malwarebytes.org/topic/181989-removal-instructions-for-yessearches/)



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/