Auteur Sujet: SweetPacks Mahjong  (Lu 8813 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25139
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
SweetPacks Mahjong
« le: juin 03, 2016, 11:39:49 »
Contenu republié avec la permission de Malwarebytes

SweetPacks Mahjong est un adware (logiciel publicitaire), qui affiche des publicités intempestives indépendantes des sites visités.

  •   S'installe en tant que programme, à l'insu de l'utilisateur ou parce qu'il n'a pas décoché les sponsors proposés lors de l'installation d'un logiciel gratuit légitime

  • SweetPacks Mahjong affiche ces différentes fenêtres pendant l'installation, qu'il faut décliner en décochant le sponsor ou par Decline







  • SweetPacks Mahjong crée des raccourcis sur le Bureau et et dans la Barre des tâches



**********

Détection de SweetPacks Mahjong dans des rapports FRST :

Citer
Free Ride Games Player (x32 Version:  - Exent Technologies Ltd) Hidden
Mahjong: Mysteries of the Past Bundle by SweetPacks (HKLM-x32\...\Mahjong: Mysteries of the Past Bundle by SweetPacks) (Version: 1.0.0.0 - SweetPacks LTD)
SweetPacks Updater (x32 Version: 4.0.1.0 - ) Hidden
ShortcutWithArgument: C:\Users\Nom_Utilisateur\Desktop\Play Mahjong Mysteries of the Past.lnk -> C:\Remote Programs\Mahjong Mysteries of the Past\GPlrLanc.exe (Exent Technologies Ltd.) -> -LOpCode 1 -shortcut hxxp://www.freeridegames.com/main/shortcut.jsp?theme=Home&AppId=765950&RunIndex=1&PrvId=143&AcID=&OpenShInIE=0&PrvDir=Default
ShortcutWithArgument: C:\Users\Nom_Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Ride Games\Mahjong Mysteries of the Past\Play Mahjong Mysteries of the Past.lnk -> C:\Remote Programs\Mahjong Mysteries of the Past\GPlrLanc.exe (Exent Technologies Ltd.) -> -LOpCode 1 -shortcut hxxp://www.freeridegames.com/main/shortcut.jsp?theme=Home&AppId=765950&RunIndex=1&PrvId=143&AcID=&OpenShInIE=0&PrvDir=Default
FirewallRules: [{B37EBFE3-95F2-470D-AE54-C0AACC7AA370}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{B1F8A31A-9FA7-4DD4-BDAC-B8129A942394}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{2F336BDD-D0F6-410B-AB92-93C4D15A381F}] => (Allow) C:\Windows\SysWOW64\ARFC\wrtc.exe
FirewallRules: [{F9D455C7-7A4D-4A5B-8CBB-7E7C63DD2997}] => (Allow) C:\Windows\SysWOW64\ARFC\wrtc.exe

() C:\Windows\System32\dmwu.exe
(Exent Technologies Ltd.) C:\Program Files (x86)\Free Ride Games\GPlayer.exe
HKU\S-1-5-19\...\Run: [Exetender] => C:\Program Files (x86)\Free Ride Games\GPlayer.exe [4932288 AAAA-MM-JJ] (Exent Technologies Ltd.)
HKU\S-1-5-20\...\Run: [Exetender] => C:\Program Files (x86)\Free Ride Games\GPlayer.exe [4932288 AAAA-MM-JJ] (Exent Technologies Ltd.)
HKCU\...\Run: [Exetender] => C:\Program Files (x86)\Free Ride Games\GPlayer.exe [4932288 AAAA-MM-JJ] (Exent Technologies Ltd.)
HKU\S-1-5-18\...\Run: [Exetender] => C:\Program Files (x86)\Free Ride Games\GPlayer.exe [4932288 AAAA-MM-JJ] (Exent Technologies Ltd.)
FF DefaultSearchEngine: SweetIM search
FF DefaultSearchUrl:
FF SelectedSearchEngine: SweetIM search
FF Homepage: hxxp://home.sweetim.com/?crg=3.49010003&ptr=100&st=12&barid={8C2FBFC5-23D7-11E6-9FA8-08002796C23D}
FF Keyword.URL: hxxp://search.sweetim.com/search.asp?src=2&ptr=100&barid={8C2FBFC5-23D7-11E6-9FA8-08002796C23D}&q=
FF Plugin-x32: @exent.com/npExentCtl,version=7.0.0.0 -> C:\Program Files (x86)\Free Ride Games\npExentCtl.dll [2009-12-27] (Exent Technologies Ltd.)
FF Plugin-x32: www.exent.com/GameTreatWidget -> C:\Program Files (x86)\Free Ride Games\NPGameTreatPlugin.dll [No File]
FF SearchPlugin: C:\Users\Nom_Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins\SweetIM Search.xml [AAAA-MM-JJ]
FF SearchPlugin: C:\Users\Nom_Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins\sweetim.xml [AAAA-MM-JJ]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [AAAA-MM-JJ]
R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1277744 AAAA-MM-JJ] ()
R2 X5XSEx_Pr143; C:\Program Files (x86)\Free Ride Games\X5XSEx_Pr143.Sys [56584 AAAA-MM-JJ] (Exent Technologies Ltd.)
U3 X5Ex_Pr143; C:\Program Files (x86)\Free Ride Games\X5Ex_Pr143.Sys [612104 AAAA-MM-JJ] (Exent Technologies Ltd.)
C:\Users\Nom_Utilisateur\Desktop\Play Free Games.lnk
C:\Users\Nom_Utilisateur\Desktop\More FREE games.lnk
C:\Users\Nom_Utilisateur\Desktop\Play Mahjong Mysteries of the Past.lnk
C:\Users\Nom_Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Ride Games
C:\Program Files (x86)\Free Ride Games
C:\Users\Public\Desktop\Play Free Games.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Free Ride Games.lnk
C:\Users\Public\Desktop\More FREE games.lnk
C:\Windows\GPlrLanc.dat
C:\ProgramData\Free Ride Games
(Exent Technologies Ltd.) C:\Windows\ExentInfo.exe
C:\Windows\SysWOW64\WNLT
C:\Windows\SysWOW64\mjcm
C:\Windows\SysWOW64\jmdp
C:\Windows\SysWOW64\ARFC
C:\Windows\system32\tprb
C:\Program Files (x86)\sweetpacks bundle uninstaller
C:\Windows\system32\dmwu.exe
(IncrediMail, Ltd.) C:\Windows\system32\ImHttpComm.dll

**********

Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable).

Citer
PUP.Optional.SweetIM
PUP.Optional.SweetPacks
PUP.Optional.Perion
PUP.Optional.InstallBrain
Adware.InstallBrain


Tutoriel d'utilisation Malwarebytes en images


Source : Removal instructions for SweetPacks Mahjong de Metallica - Malwarebytes Forums



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/