Security-X

Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le juillet 20, 2017, 14:57:14

Titre: Easy Classifieds Access
Posté par: chantal11 le juillet 20, 2017, 14:57:14
Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)

Easy Classifieds Access est un Browser Hijacker (pirate de navigateur) qui modifie les paramètres du navigateur (page d’accueil , page de recherche, ....) afin de forcer la consultation du site ciblé et affiche aussi des publicités.
Easy Classifieds Access appartient à la famille Spigot (Spigot browser hijackers (https://blog.malwarebytes.com/puppum/2017/02/spigot-browser-hijackers/))

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/EasyClassifiedsAccess/warning4.png&key=62560b3bbdf272918185695a4ff3d4360ac49bd48bb43f4c789ede52e367f9e7)

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/EasyClassifiedsAccess/warning1.png&key=2cad5b4da11f87169af6ea8a5e571c1c393b4c7f1cb8e87fe4fab09c9daea169)

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/EasyClassifiedsAccess/warning2.png&key=b5156b6f74d7f358e2ddf8a6d4ffbabc4af05bf21d267b27ff87edbbc58d886b)

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/EasyClassifiedsAccess/warning5.png&key=41b6c661e8a0d2dbb34da60f35702223e821d18b57397ca004b72a343eba8e17)

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/EasyClassifiedsAccess/startpage.png&key=4fcaedad617f51881a4987249367b02ba669f8216e2740153dc2c4bf553dbabd)


(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/EasyClassifiedsAccess/warning3.png&key=d873c36f8ff068627953089959d46bce22ba30194f74379349b07d390d3ff95d)

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/EasyClassifiedsAccess/warning6.png&key=5d5b5a32c0d32f15e0fdbc2b45f6301ee904a208c0f04c7a767ebd04fa3027f2)







**********

Détection de Easy Classifieds Access dans des rapports FRST :

Citer
Easy Classifieds Access (HKCU\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 2.7.0.2 - Cloud Installer)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.easyclassifiedsaccess.com/?source=-bb8&uid={uid1}&uc={date}&ap=&i_id=classifieds__1.30
SearchScopes: HKCU -> DefaultScope {A3955D22-9D84-4411-83C3-D453496368EA} URL = hxxp://search.easyclassifiedsaccess.com/s?source=-bb8&uid={uid1}&uc={date}&ap=&i_id=classifieds__1.30&query={searchTerms}
SearchScopes: HKCU -> {A3955D22-9D84-4411-83C3-D453496368EA} URL = hxxp://search.easyclassifiedsaccess.com/s?source=-bb8&uid={uid1}&uc={date}&ap=&i_id=classifieds__1.30&query={searchTerms}
FF NewTab: hxxp://search.easyclassifiedsaccess.com?uid=19a043f9-8f30-4569-a7e6-32159f35759b&uc={date}&ap=0&source=tt&page=newtab&implementation_id=classifieds_0.2.0
FF Homepage: hxxp://search.easyclassifiedsaccess.com?uid=19a043f9-8f30-4569-a7e6-32159f35759b&uc={date}&ap=0&source=tt&page=homepage&implementation_id=classifieds_0.2.0
FF Extension: Classifieds - C:\Users\{Nom_Utilisateur}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\@Classifieds.xpi [2017-06-16]
C:\Users\{Nom_Utilisateur}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}



**********

Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable)
Sous la version Premium, Malwarebytes bloque le domaine easyclassifiedsaccess.com et l'IP 174.129.214.120

Citer
PUP.Optional.Spigot
PUP.Optional.Spigot.Generic

Citer
-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 2
PUP.Optional.Spigot, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [657], [373878],1.0.2163
PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A3955D22-9D84-4411-83C3-D453496368EA}, Delete-on-Reboot, [2047], [368913],1.0.2163

Registry Value: 1
PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A3955D22-9D84-4411-83C3-D453496368EA}|URL, Delete-on-Reboot, [2047], [368913],1.0.2163

Registry Data: 1
PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [2047], [373048],1.0.2163

Data Stream: 0
(No malicious items detected)

Folder: 3
PUP.Optional.Spigot, C:\USERS\{username}\APPDATA\ROAMING\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [657], [373878],1.0.2163
PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Classifieds\simple-storage, Delete-on-Reboot, [2047], [361533],1.0.2163
PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}.default\JETPACK\@CLASSIFIEDS, Delete-on-Reboot, [2047], [361533],1.0.2163

File: 5
PUP.Optional.Spigot, C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\Uninstall.exe, Delete-on-Reboot, [657], [373878],1.0.2163
PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Classifieds\simple-storage\store.json, Delete-on-Reboot, [2047], [361533],1.0.2163
PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}.default\PREFS.JS, Replaced, [2047], [361537],1.0.2163
PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}.default\PREFS.JS, Replaced, [2047], [361538],1.0.2163
PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}.default\EXTENSIONS\@CLASSIFIEDS.XPI, Delete-on-Reboot, [2047], [361542],1.0.2163

Physical Sector: 0
(No malicious items detected)


Tutoriel d'utilisation Malwarebytes en images (https://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-22723/)


Source : Removal instructions for Easy Classifieds Access de Metallica - Malwarebytes Forums (https://forums.malwarebytes.com/topic/202772-removal-instructions-for-easy-classifieds-access/)



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/