Auteur Sujet: RuntimeBroker  (Lu 15453 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25133
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
RuntimeBroker
« le: juillet 06, 2017, 17:29:44 »
Contenu republié avec la permission de Malwarebytes

RuntimeBroker est un adware (logiciel publicitaire), qui affiche des publicités intempestives indépendantes des sites visités.
RuntimeBroker utilise le proxy Privoxy pour intercepter et modifier votre trafic Internet.

  • Paramètre un proxy dans les Options Internet

http://








**********

Détection de RuntimeBroker dans des rapports FRST :

Citer
() C:\Windows\{username}-pc\mgwz.dll

(The Privoxy team - www.privoxy.org) C:\Windows\{Nom_Utilisateur}-pc\oxy.exe
ProxyEnable: [{SID Utilisateur}] => Proxy is enabled.
ProxyServer: [{SID Utilisateur}] => 127.0.0.1:8118
S2 RuntimeBroker; C:\Windows\{Nom_Utilisateur}-pc\RuntimeBroker.exe [349184 2017-04-25] (www.kdsmarketing.com) [File not signed]
R2 Telephone; C:\Windows\{Nom_Utilisateur}-pc\oxy.exe [373248 2016-01-22] (The Privoxy team - www.privoxy.org) [File not signed]
C:\Windows\{Nom_Utilisateur}-pc


**********

Détecté et traité par Malwarebytes en tant que Adware (logiciel publicitaire)
Sous la version Premium, Malwarebytes bloque le domaine offersonly4u.com et l'IP 127.42.0.2

Citer
Adware.Privoxy
PUM.Optional.ProxyHijacker

Citer
-Scan Details-
Process: 1
Adware.Privoxy, C:\WINDOWS\{computername}\OXY.EXE, Quarantined, [1506], [385808],1.0.2261

Module: 1
Adware.Privoxy, C:\WINDOWS\{computername}\OXY.EXE, Quarantined, [1506], [385808],1.0.2261

Registry Key: 5
Trojan.SpamBot, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RuntimeBroker, Delete-on-Reboot, [582], [402529],1.0.2261
Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TELEPHONE, Delete-on-Reboot, [1506], [385808],1.0.2261
Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Telephone, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RuntimeBroker, Delete-on-Reboot, [1506], [-1],0.0.0

Registry Value: 7
Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TELEPHONE|IMAGEPATH, Delete-on-Reboot, [1506], [385808],1.0.2261
Adware.Privoxy, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1506], [-1],0.0.0
PUM.Optional.ProxyHijacker, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [9480], [250493],1.0.2261

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 5
Trojan.SpamBot, C:\WINDOWS\{computername}\RUNTIMEBROKER.EXE, Delete-on-Reboot, [582], [402529],1.0.2261
Trojan.SpamBot, C:\USERS\{username}\DESKTOP\OFFERS.EXE, Delete-on-Reboot, [582], [402481],1.0.2261
Adware.Privoxy, C:\WINDOWS\{computername}\OXY.EXE, Delete-on-Reboot, [1506], [385808],1.0.2261
Adware.Privoxy, C:\WINDOWS\{computername}\oxy.exe, Delete-on-Reboot, [1506], [-1],0.0.0
Adware.Privoxy, C:\WINDOWS\{computername}\RuntimeBroker.exe, Delete-on-Reboot, [1506], [-1],0.0.0

Physical Sector: 0
(No malicious items detected)


Tutoriel d'utilisation Malwarebytes en images


Source : Removal instructions for RuntimeBroker de Metallica - Malwarebytes Forums



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/