Security-X

Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le novembre 10, 2016, 10:42:49

Titre: Safe Finder widget
Posté par: chantal11 le novembre 10, 2016, 10:42:49
Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)

Safe Finder widget est un Browser Hijacker (pirate de navigateur) qui modifie les paramètres du navigateur (page d’accueil , page de recherche, ....) afin de forcer la consultation du site ciblé.


(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/SafeFinder2/warning4.png&key=4398f1f5ca214c6fce4003bc7a49627fde80f4833c30b95110a6d7bd1a386b7d)

(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/SafeFinder2/main.png&key=9414b0c354bba8bdca29157ff86878d7d63e55bf8d34229b8e290131776c4f36)

(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/SafeFinder2/warning1.png&key=341fcabd4dd49b565ceb6eee68ac286beb360676a47411cfdb8b3312c572db4b)

(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/SafeFinder2/warning2.png&key=657641cec4dd94ce2f7beaaee699e907fae203804f9912ca8b7e224257c4ad28)

(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/SafeFinder2/icons.png&key=d0d28284f08053858de9d71453716ab3882488f32845ea3d534c5315daf65313)


(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/SafeFinder2/searchsite.png&key=895172f7713c56bfe0e8ddfee2de1f67e70cfcd0eb30829d7342e2943b576890)





**********

Détection de Safe Finder widget dans des rapports FRST :

Citer
SafeFinder (HKLM-x32\...\{5BECDE00-F7D5-4635-AE15-9191755DFF85}) (Version: 1.0.0.0 - Linkury) <==== ATTENTION

() C:\ProgramData\SafeFinder\SafeFinder.exe
() C:\Program Files (x86)\ProductUI\Startup.exe
HKLM\...\Run: [smrt] => C:\Program Files (x86)\ProductUI\Startup.exe [78848 2016-04-05] ()
AppInit_DLLs: C:\ProgramData\SafeFinder\Subhold.dll => C:\ProgramData\SafeFinder\Subhold.dll [368744 2016-11-09] ()
AppInit_DLLs-x32: C:\ProgramData\SafeFinder\Isnimlux.dll => C:\ProgramData\SafeFinder\Isnimlux.dll [263272 2016-11-09] ()
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRCZciw56u8F4OmHlUQh95h8Pc8ba5PjQ8E-hUucQPDy8nG-nIK_2MTjCqjbuXDpgXzEesHAlHzlhDIV6WmmzOzGNXJJOJM,
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
SearchScopes: HKCU -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
SearchScopes: HKCU -> {ielnksrch} URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
FF NewTab: C:\\ProgramData\\SafeFinders\\ff.NT
FF Homepage: C:\\ProgramData\\SafeFinders\\ff.HP
CHR HomePage: Default -> hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyECg85kvzo0VRu3SzW3wQTwAEA3uX4DxidHj1C8x_SRFYv4f1SvJexDL57RPIsc2oZd6t3zVs-r_rG5QYF2Hm5W0kQUmI,
CHR DefaultSearchURL: Default -> hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyISOLnuZlvHWH08PEUZnPUQOeymjN2QbPv8VoC6AyPjRV3F2b39dW_5bP1k93z9nAuoFk5xuCDrIvJZhhisQlaOCRG_S8,&q={searchTerms}
CHR DefaultSearchKeyword: Default -> feed.sonic-search.com
R2 SafeFinder; C:\ProgramData\\SafeFinder\\SafeFinder.exe [770152 2016-04-21] ()
C:\Windows\SysWOW64\findit.xml
C:\ProgramData\SafeFinders
C:\Program Files (x86)\ProductUI
(SlimDesktop) C:\Users\{Nom_Utilisateur}\AppData\Roaming\OverFan.bin
C:\ProgramData\SafeFinder
C:\Users\{Nom_Utilisateur}\AppData\Roaming\agent.dat
C:\Users\{Nom_Utilisateur}\AppData\Roaming\Alphakix.tst
C:\Users\{Nom_Utilisateur}\AppData\Roaming\Installer.dat
C:\Users\{Nom_Utilisateur}\AppData\Roaming\noah.dat
C:\Users\{Nom_Utilisateur}\AppData\Roaming\Config.xml
C:\Users\{Nom_Utilisateur}\AppData\Roaming\Main.dat
C:\Users\{Nom_Utilisateur}\AppData\Roaming\InstallationConfiguration.xml
C:\Users\{Nom_Utilisateur}\AppData\Roaming\md.xml
C:\Users\{Nom_Utilisateur}\AppData\Roaming\Alphakix.exe
() C:\Users\{Nom_Utilisateur}\AppData\Roaming\uninstall_temp.ico



**********

Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable)

Citer
PUP.Optional.Linkury


Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)


Source : Removal instructions for Safe Finder widget de Metallica - Malwarebytes Forums (https://forums.malwarebytes.org/topic/190368-removal-instructions-for-safe-finder-widget/)



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/