Auteur Sujet: Safe Finder widget  (Lu 8935 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25130
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
Safe Finder widget
« le: novembre 10, 2016, 10:42:49 »
Contenu republié avec la permission de Malwarebytes

Safe Finder widget est un Browser Hijacker (pirate de navigateur) qui modifie les paramètres du navigateur (page d’accueil , page de recherche, ....) afin de forcer la consultation du site ciblé.


  • S'installe en tant que programme, à l'insu de l'utilisateur ou parce qu'il n'a pas décoché les sponsors proposés lors de l'installation d'un logiciel gratuit légitime

  • Affiche ces alertes pendant l'installation



  • Safe Finder widget modifie les paramètres de recherche dans Chrome et Internet Explorer



  • Installe ce widget sur le côté droit du Bureau

  • Affiche cette page de démarrage dans le navigateur






**********

Détection de Safe Finder widget dans des rapports FRST :

Citer
SafeFinder (HKLM-x32\...\{5BECDE00-F7D5-4635-AE15-9191755DFF85}) (Version: 1.0.0.0 - Linkury) <==== ATTENTION

() C:\ProgramData\SafeFinder\SafeFinder.exe
() C:\Program Files (x86)\ProductUI\Startup.exe
HKLM\...\Run: [smrt] => C:\Program Files (x86)\ProductUI\Startup.exe [78848 2016-04-05] ()
AppInit_DLLs: C:\ProgramData\SafeFinder\Subhold.dll => C:\ProgramData\SafeFinder\Subhold.dll [368744 2016-11-09] ()
AppInit_DLLs-x32: C:\ProgramData\SafeFinder\Isnimlux.dll => C:\ProgramData\SafeFinder\Isnimlux.dll [263272 2016-11-09] ()
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRCZciw56u8F4OmHlUQh95h8Pc8ba5PjQ8E-hUucQPDy8nG-nIK_2MTjCqjbuXDpgXzEesHAlHzlhDIV6WmmzOzGNXJJOJM,
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
SearchScopes: HKCU -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
SearchScopes: HKCU -> {ielnksrch} URL = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyfAvkotptyR-vsRxaIg0cFPDu_Xozpfm67ZcOL2l75-bVpruz0sE5gXCz6D1Le9iQ2XsbrqABGF8tlE5rMXis2F5E1V0Q,&q={searchTerms}
FF NewTab: C:\\ProgramData\\SafeFinders\\ff.NT
FF Homepage: C:\\ProgramData\\SafeFinders\\ff.HP
CHR HomePage: Default -> hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyECg85kvzo0VRu3SzW3wQTwAEA3uX4DxidHj1C8x_SRFYv4f1SvJexDL57RPIsc2oZd6t3zVs-r_rG5QYF2Hm5W0kQUmI,
CHR DefaultSearchURL: Default -> hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRbPPu-brYsVApIPOERS58GcQeivu6iPL1Ne74nne9omldl6NEnXgUnm5V1HwDNYEApmRO7x45JUfiBePj2SfeEuXuiXuTJiudSgPGRyISOLnuZlvHWH08PEUZnPUQOeymjN2QbPv8VoC6AyPjRV3F2b39dW_5bP1k93z9nAuoFk5xuCDrIvJZhhisQlaOCRG_S8,&q={searchTerms}
CHR DefaultSearchKeyword: Default -> feed.sonic-search.com
R2 SafeFinder; C:\ProgramData\\SafeFinder\\SafeFinder.exe [770152 2016-04-21] ()
C:\Windows\SysWOW64\findit.xml
C:\ProgramData\SafeFinders
C:\Program Files (x86)\ProductUI
(SlimDesktop) C:\Users\{Nom_Utilisateur}\AppData\Roaming\OverFan.bin
C:\ProgramData\SafeFinder
C:\Users\{Nom_Utilisateur}\AppData\Roaming\agent.dat
C:\Users\{Nom_Utilisateur}\AppData\Roaming\Alphakix.tst
C:\Users\{Nom_Utilisateur}\AppData\Roaming\Installer.dat
C:\Users\{Nom_Utilisateur}\AppData\Roaming\noah.dat
C:\Users\{Nom_Utilisateur}\AppData\Roaming\Config.xml
C:\Users\{Nom_Utilisateur}\AppData\Roaming\Main.dat
C:\Users\{Nom_Utilisateur}\AppData\Roaming\InstallationConfiguration.xml
C:\Users\{Nom_Utilisateur}\AppData\Roaming\md.xml
C:\Users\{Nom_Utilisateur}\AppData\Roaming\Alphakix.exe
() C:\Users\{Nom_Utilisateur}\AppData\Roaming\uninstall_temp.ico



**********

Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable)

Citer
PUP.Optional.Linkury


Tutoriel d'utilisation Malwarebytes en images


Source : Removal instructions for Safe Finder widget de Metallica - Malwarebytes Forums



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/