Security-X

Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le juillet 06, 2017, 17:29:44

Titre: RuntimeBroker
Posté par: chantal11 le juillet 06, 2017, 17:29:44
Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)

RuntimeBroker est un adware (logiciel publicitaire), qui affiche des publicités intempestives indépendantes des sites visités.
RuntimeBroker utilise le proxy Privoxy pour intercepter et modifier votre trafic Internet.


(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/RuntimeBroker/warning5.png&key=5feb37609e94d43ec9c5224c17f843546f6a65ac01f6d3a1d8c017635b326798)http://








**********

Détection de RuntimeBroker dans des rapports FRST :

Citer
() C:\Windows\{username}-pc\mgwz.dll

(The Privoxy team - www.privoxy.org) C:\Windows\{Nom_Utilisateur}-pc\oxy.exe
ProxyEnable: [{SID Utilisateur}] => Proxy is enabled.
ProxyServer: [{SID Utilisateur}] => 127.0.0.1:8118
S2 RuntimeBroker; C:\Windows\{Nom_Utilisateur}-pc\RuntimeBroker.exe [349184 2017-04-25] (www.kdsmarketing.com) [File not signed]
R2 Telephone; C:\Windows\{Nom_Utilisateur}-pc\oxy.exe [373248 2016-01-22] (The Privoxy team - www.privoxy.org) [File not signed]
C:\Windows\{Nom_Utilisateur}-pc


**********

Détecté et traité par Malwarebytes en tant que Adware (logiciel publicitaire)
Sous la version Premium, Malwarebytes bloque le domaine offersonly4u.com et l'IP 127.42.0.2

Citer
Adware.Privoxy
PUM.Optional.ProxyHijacker

Citer
-Scan Details-
Process: 1
Adware.Privoxy, C:\WINDOWS\{computername}\OXY.EXE, Quarantined, [1506], [385808],1.0.2261

Module: 1
Adware.Privoxy, C:\WINDOWS\{computername}\OXY.EXE, Quarantined, [1506], [385808],1.0.2261

Registry Key: 5
Trojan.SpamBot, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RuntimeBroker, Delete-on-Reboot, [582], [402529],1.0.2261
Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TELEPHONE, Delete-on-Reboot, [1506], [385808],1.0.2261
Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Telephone, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RuntimeBroker, Delete-on-Reboot, [1506], [-1],0.0.0

Registry Value: 7
Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TELEPHONE|IMAGEPATH, Delete-on-Reboot, [1506], [385808],1.0.2261
Adware.Privoxy, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1506], [-1],0.0.0
PUM.Optional.ProxyHijacker, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [9480], [250493],1.0.2261

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 5
Trojan.SpamBot, C:\WINDOWS\{computername}\RUNTIMEBROKER.EXE, Delete-on-Reboot, [582], [402529],1.0.2261
Trojan.SpamBot, C:\USERS\{username}\DESKTOP\OFFERS.EXE, Delete-on-Reboot, [582], [402481],1.0.2261
Adware.Privoxy, C:\WINDOWS\{computername}\OXY.EXE, Delete-on-Reboot, [1506], [385808],1.0.2261
Adware.Privoxy, C:\WINDOWS\{computername}\oxy.exe, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, C:\WINDOWS\{computername}\RuntimeBroker.exe, Delete-on-Reboot, [1506], [-1],0.0.0

Physical Sector: 0
(No malicious items detected)


Tutoriel d'utilisation Malwarebytes en images (https://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-22723/)


Source : Removal instructions for RuntimeBroker de Metallica - Malwarebytes Forums (https://forums.malwarebytes.com/topic/203505-removal-instructions-for-runtimebroker/)



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/