Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)
InspiringBackgrounds est un Browser Hijacker (pirate de navigateur) qui modifie les paramètres du navigateur (page d’accueil , page de recherche, ....) afin de forcer la consultation du site ciblé.
InspiringBackgrounds est une barre d’outils de Mindspark/Ask toolbar (https://blog.malwarebytes.org/malvertising-2/2014/11/mindspark-toolbars/) maintenant connu comme des Applications IAC.
- S'installe en tant que programme, à l'insu de l'utilisateur ou parce qu'il n'a pas décoché les sponsors proposés lors de l'installation d'un logiciel gratuit légitime
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/InspiringBackgrounds/warning4.png&key=0c9133c5a2d28702c9c6bf6919fa75be849ce6b652f68836af815eb4093bc838)
- Affiche ces alertes pendant l'installation
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/InspiringBackgrounds/site.png&key=8cf2abf239cb2db933b97e1621f71a5ac2dced76937c589c9dec94c3dfa4adff)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/InspiringBackgrounds/warning5.png&key=279c1bf4241048c94fdbbbdcada8433610350690ef8aa7de5dbe3f97d596f8c4)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/InspiringBackgrounds/warning6.png&key=ea6052cfee722d4c54029b7efe158dc9207d30935f9977f0b883e732345696e6)
- InspiringBackgrounds s'installe en tant qu'extension/add-on du navigateur
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/InspiringBackgrounds/warning1.png&key=c3524f6200929c59eebddb0f095fa1a66e0036414c2ee34aec54d18136037781)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/InspiringBackgrounds/warning2.png&key=bb8761f2b8a5b1c8aabc80613e717cc5b530a5fe6004ea373b7f6b6bc8124ac5)
- Affiche cette page de démarrage dans le navigateur
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/InspiringBackgrounds/main.png&key=9d402a15d0ac06421269e3a6e03a1bfc26d7710d4d34e2500e79a4275ee71dc9)
**********
Détection de InspiringBackgrounds dans des rapports FRST :
InspiringBackgrounds Internet Explorer Homepage and New Tab (HKCU\...\InspiringBackgroundsTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network) <==== ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp.myway.com/inspiringbackgrounds/ttab02/index.html?n={n1}&p2={p21}&ptb={ptb1}
FF Homepage: hxxp://hp.myway.com/inspiringbackgrounds/ttab02/index.html?coId={coid1}&subId&ln=en&n={n2}&ptb={ptb2}&st=tab&p2={p22}&si
FF Extension: InspiringBackgrounds - C:\Users\{Nom_Utilisateur}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\_iyMembers_@free.inspiringbackgrounds.com [2016-10-13]
CHR Extension: (InspiringBackgrounds) - C:\Users\{Nom_Utilisateur}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mknhnhgoeomafmbgfbppcgacgcbokbnn [2016-10-13]
C:\Users\{Nom_Utilisateur}\AppData\Local\InspiringBackgroundsTooltab
**********
Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable)
PUP.Optional.MindSpark
Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)
Source : Removal instructions for InspiringBackgrounds de Metallica - Malwarebytes Forums (https://forums.malwarebytes.org/topic/189356-removal-instructions-for-inspiringbackgrounds/)
Toujours infecté ? Une question avant de faire des manipulations ?
Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/ en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/