Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)
Youndoo est un Browser Hijacker (pirate de navigateur) qui modifie les paramètres du navigateur (page d’accueil , page de recherche, ....) afin de forcer la consultation du site ciblé et affiche aussi des publicités.
Youndoo appartient à la famille GsearchFinder (https://blog.malwarebytes.com/cybercrime/2016/04/gsearchfinder-hijackers-add-extra-firefox-profile/) qui ajoute un profil supplémentaire Firefox.
- S'installe en tant que programme, à l'insu de l'utilisateur ou parce qu'il n'a pas décoché les sponsors proposés lors de l'installation d'un logiciel gratuit légitime
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FYoundoo%2Fwarning4.png&key=01f35e51ae0c0f01b8fae7833af9a5907cefcec1b921860650027b952bd628a1)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FYoundoo%2Fwarning1.png&key=5e42e8c30baf8d438d875faec13f63b7386b349db82d4afdd4279a5da315c23f)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FYoundoo%2Fwarning2.png&key=80085ee0b61f141c214f565160113ab7c6adccd247f36965037933a1f3fe3f87)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FYoundoo%2Fwarning3.png&key=3c3cb2e1ff11210633c02a5d83a2f8be1bf15a2773f4a58a3a8636731cbc63a7)
**********
Détection de Youndoo dans des rapports FRST :
youndoo - Uninstall (HKLM-x32\...\{61FC6201-6727-43A3-ADFF-A360F9817331}) (Version: - )
Task: {48BD166D-DC7D-484A-BE0B-B9D487A4D21D} - System32\Tasks\Plohis Adapter => C:\Program Files (x86)\Bevconesy\plohisAdapterGrq.exe [AAAA-MM-JJ] ()
() C:\Users\Nom_Utilisateur\AppData\Roaming\Microsoft\Windows\Cookies\werrise.dll
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
ShellExecuteHooks: - {6710C780-E20E-4C49-A87D-321850ED3D7C} - C:\Users\Nom_Utilisateur\AppData\Roaming\Microsoft\Windows\Cookies\werrise.dll [388096 AAAA-MM-JJ] ()
FF ProfilePath: C:\Users\Nom_Utilisateur\AppData\Roaming\Profiles\8ntoizyz.default
FF NewTab: hxxp://www.youndoo.com/?z={z1}&from=btp&uid=VBOXXHARDDISK_VB3361b1e7-85c503b7&type=hp
FF DefaultSearchEngine: youndoo
FF SelectedSearchEngine: youndoo
FF Homepage: hxxp://www.youndoo.com/?z={z1}&from=btp&uid={harddiskID}&type=hp
FF SearchPlugin: C:\Users\Nom_Utilisateur\AppData\Roaming\Profiles\8ntoizyz.default\searchplugins\xirzzddp.xml [AAAA-MM-JJ]
FF Extension: GsearchFinder - C:\Users\Nom_Utilisateur\AppData\Roaming\Profiles\8ntoizyz.default\Extensions\@90B817C8-8A5C-413B-9DDD-B2C61ED6E79A.xpi [AAAA-MM-JJ]
CHR HomePage: lirosyhizetheratbther -> hxxp://www.youndoo.com/?z={z1}&from=btp&uid={harddiskID}&type=hp
CHR StartupUrls: lirosyhizetheratbther -> "hxxp://www.youndoo.com/?z={z1}&from=btp&uid={harddiskID}&type=hp"
CHR DefaultSearchURL: lirosyhizetheratbther -> hxxp://www.youndoo.com/search/?q={searchTerms}&z={z1}&from=btp&uid={harddiskID}&type=sp
CHR DefaultSearchKeyword: lirosyhizetheratbther -> youndoo
S2 plohisAdapterArw.exe; C:\Program Files (x86)\Bevconesy\plohisAdapterArw.exe [708896 AAAA-MM-JJ] ()
C:\Windows\System32\Tasks\Plohis Adapter
C:\Users\Nom_Utilisateur\AppData\Local\grizosyanqshbuzersp
C:\Program Files (x86)\Bevconesy
**********
Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable)
PUP.Optional.Youndoo
PUP.Optional.YesSearches
PUP.Optional.GsearchFinder
Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)
Source : Removal instructions for Youndoo de Metallica - Malwarebytes Forums (https://forums.malwarebytes.org/topic/185148-removal-instructions-for-youndoo/)
Toujours infecté ? Une question avant de faire des manipulations ?
Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/ en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/