Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)
greenmartmediaads est un adware (logiciel publicitaire), qui affiche des publicités intempestives indépendantes des sites visités.
- Modifie les paramètres d'Internet Explorer et paramétre un proxy
(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/FlexartPrivoxy/warning1.png&key=6076faff98a86f6334bfe54c0b56bcaba9a354f46e515d8d5b8967825e005cd8)
- Est installé avec un autre logiciel nommé Flexart Setup
(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/FlexartPrivoxy/FileDetails.png&key=981a15eb44737db0ada3d6d4e2108db4312309ebaf38d903a3774ef3ab83b3d2)
**********
Détection de greenmartmediaads dans des rapports FRST :
() C:\Windows\{Nom_PC}_030317\mgwz.dll
The Privoxy team - www.privoxy.org) C:\Windows\{Nom_PC}_030317\oxy.exe
(greenmartmediaads) C:\Windows\{Nom_PC}_030317\Windebug.exe
ProxyEnable: [{user SID}] => Proxy is enabled.
ProxyServer: [{user SID}] => 127.0.0.1:8118
R2 Telephone; C:\Windows\{Nom_PC}_030317\oxy.exe [373248 2016-01-22] (The Privoxy team - www.privoxy.org) [File not signed]
R2 Windefender; C:\Windows\{Nom_PC}_030317\Windebug.exe [3413504 2017-03-03] (greenmartmediaads) [File not signed]
C:\Windows\{Nom_PC}_030317
**********
Détecté et traité par Malwarebytes en tant que Adware (logiciel publicitaire) et Trojan Dropper
Sous la version Premium, Malwarebytes bloque le domaine greenmartmediaads.com et l'IP 104.27.152.224
Adware.Privoxy
Trojan.Dropper
PUP.Optional.Privoxy
PUM.Optional.ProxyHijacker
Tutoriel d'utilisation Malwarebytes en images (https://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-22723/)
Source : Removal instructions for greenmartmediaads de Metallica - Malwarebytes Forums (https://forums.malwarebytes.com/topic/199245-removal-instructions-for-greenmartmediaads/)
Toujours infecté ? Une question avant de faire des manipulations ?
Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/ en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/