SProtector est un programme qui s’installe généralement à votre insu via le téléchargement de logiciels gratuits. Recensé le 02/05/2014

Caractéristiques

– Il appartient à une famille de PUP Optionnels (Potentially Unwanted Program).
– Vendeur : PUP.Optional.

Actions principales

– Il s’installe en tant que Browser Helper Object (BHO) de Navigateur internet (O2),
– Il s’installe en tant que service pour être lancé à chaque démarrage du système (O23),(SS/SR),
– Il démarre une tâche planifiée en automatique (O39),
– Il s’installe en tant que programme (O42),
– Il crée de multiples clés de Registre « Software »,
– Il crée des dossiers supplémentaires (O43),

Aperçu ZHPDiag

—\\ Browser Helper Objects de navigateur (O2)
O2 – BHO: FuNDeaalss

[64Bits] – {0EA6A3F5-C0C9-AA1E-120F-6BD41323017D} Clé orpheline
O2 – BHO: AllCheapoPorIcee [64Bits] – {370DDBDB-B9BC-598F-D988-A75EBC5A02C4} Clé orpheline
O2 – BHO: DigiiSaver [64Bits] – {DC8E3148-F9CC-6459-4F4F-5502E76CE9C7} Clé orpheline

—\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 – Service: Network Acceleration (2384af53) . (…) – c:\progra~3\networ~1\NetworkAccelerationSvc.dll
O23 – Service: Filteligent (3f0ddfac) . (…) – c:\progra~3\filtel~1\FilteligentSvc.dll
O23 – Service: Smooth Browsing (4ccdc918) . (…) – c:\progra~3\smooth~1\SmoothBrowsingSvc.dll
O23 – Service: Browser System Enahncer (671c50b0) . (…) – c:\progra~3\browse~1\BrowserSystemEnahncerSvc.dll
O23 – Service: WinWeb protection (89f7ebe4) . (…) – c:\progra~3\winweb~1\WinWebprotectionSvc.dll
O23 – Service: Winclean performap (def8540c) . (…) – c:\progra~3\wincle~1\WincleanperformapSvc.dll
O23 – Service: Performancer (dfc86759) . (…) – c:\progra~3\perfor~1\PerformancerSvc.dll
O23 – Service: WinSpeed (f1f78e38) . (…) – c:\progra~3\winspeed\WinSpeedSvc.dll
O23 – Service: Winclean performap (def8540c) . (…) – c:\progra~3\wincle~1\WincleanperformapSvc.dll

—\\ Tâches planifiées en automatique (O39)
O39 – APT: GS.Enabler-S-1824435291 – (…) — C:\Windows\Tasks\GS.Enabler-S-1824435291.job [474] O39 – APT: GS.Enabler-S-1824435291 – (…) — C:\Windows\System32\Tasks\GS.Enabler-S-1824435291 [474]

—\\ Logiciels installés (O42)
O42 – Logiciel: Browser System Enahncer – (.Linker Ltd.) [HKLM][64Bits] — {5F189DF5-2D05-472B-9091-84D9848AE48B}{671c50b0}
O42 – Logiciel: EnnjoyCoupon – (.EnjoyCoupoN.) [HKLM][64Bits] — {2DF3E224-05CD-4113-AA7A-86F2F6607B46}
O42 – Logiciel: Filteligent – (.Winteam.) [HKLM][64Bits] — {5F189DF5-2D05-472B-9091-84D9848AE48B}{3f0ddfac}
O42 – Logiciel: IePluginService12.27.0.3292 – (.Cherished Technololgy LIMITED.) [HKLM][64Bits] — IePlugins
O42 – Logiciel: Network Acceleration – (.Goingo.) [HKLM][64Bits] — {5F189DF5-2D05-472B-9091-84D9848AE48B}{2384af53}
O42 – Logiciel: Smooth Browsing – (.Team Work.) [HKLM][64Bits] — {5F189DF5-2D05-472B-9091-84D9848AE48B}{4ccdc918}
O42 – Logiciel: WinSpeed – (.Sourceplace.) [HKLM][64Bits] — {5F189DF5-2D05-472B-9091-84D9848AE48B}{f1f78e38}
O42 – Logiciel: WinWeb protection – (.Zilware.) [HKLM][64Bits] — {5F189DF5-2D05-472B-9091-84D9848AE48B}{89f7ebe4}
O42 – Logiciel: Winclean performap – (.PlanetCore.) [HKLM][64Bits] — {5F189DF5-2D05-472B-9091-84D9848AE48B}{def8540c}
O42 – Logiciel: IePluginService 12.27.0.3326 – (.Cherished Technololgy LIMITED.) [HKLM][64Bits] — IePlugins
O42 – Logiciel: Winclean performap – (.GreatSoft.) [HKLM][64Bits] — {5F189DF5-2D05-472B-9091-84D9848AE48B}{def8540c}

—\\ HKCU & HKLM Software Keys
[HKCU\Software\45914InstEnd] [HKLM\Software\Wow6432Node\IePlugin] [HKLM\Software\Wow6432Node\GS.Enabler]

—\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 – CFD: 28/12/2013 – 0:04:08 – [8,406] —-D C:\ProgramData\Browser System Enahncer
O43 – CFD: 14/01/2014 – 14:11:05 – [0,007] —-D C:\ProgramData\DigiiSaver
O43 – CFD: 31/12/2013 – 10:16:51 – [0,035] —-D C:\ProgramData\fc7f3e65672b9cea
O43 – CFD: 29/12/2013 – 18:58:30 – [8,371] —-D C:\ProgramData\Filteligent
O43 – CFD: 14/01/2014 – 14:11:05 – [0,007] —-D C:\ProgramData\FuNDeaalss
O43 – CFD: 13/01/2014 – 0:24:30 – [0,479] —-D C:\ProgramData\IePluginService
O43 – CFD: 31/12/2013 – 10:16:37 – [0,007] —-D C:\ProgramData\ighfdodmghgponecehdilnfepioockfm
O43 – CFD: 30/12/2013 – 21:24:36 – [8,275] —-D C:\ProgramData\Network Acceleration
O43 – CFD: 30/12/2013 – 9:05:35 – [8,430] —-D C:\ProgramData\Smooth Browsing
O43 – CFD: 01/01/2014 – 8:28:08 – [8,249] —-D C:\ProgramData\Winclean performap
O43 – CFD: 14/01/2014 – 14:18:03 – [4,175] —-D C:\ProgramData\WinSpeed
O43 – CFD: 27/12/2013 – 22:23:56 – [8,294] —-D C:\ProgramData\WinWeb protection
O43 – CFD: 14/01/2014 – 14:11:05 – [0,007] —-D C:\ProgramData\AllCheapoPorIcee
O43 – CFD: 25/01/2014 – 12:03:15 – [0,484] —-D C:\ProgramData\IePluginService
O43 – CFD: 26/01/2014 – 00:29:58 – [4,357] —-D C:\ProgramData\Winclean performap
O43 – CFD: 10/03/2014 – 15:42:15 – [4,212] —-D C:\ProgramData\Accelesys

—\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS – | Auto 27/12/2013 180560 | c:\progra~3\winspeed\WinSpeedSvc.dll (f1f78e38) . (…) – C:\ProgramData\WinSpeed\WinSpeedSvc.dll
SR – | Auto 30/12/2013 181584 | c:\progra~3\networ~1\NetworkAccelerationSvc.dll (2384af53) . (…) – C:\ProgramData\Network Acceleration\NetworkAccelerationSvc.dll
SR – | Auto 29/12/2013 179024 | c:\progra~3\filtel~1\FilteligentSvc.dll (3f0ddfac) . (…) – C:\ProgramData\Filteligent\FilteligentSvc.dll
SR – | Auto 30/12/2013 179024 | c:\progra~3\smooth~1\SmoothBrowsingSvc.dll (4ccdc918) . (…) – C:\ProgramData\Smooth Browsing\SmoothBrowsingSvc.dll
SR – | Auto 28/12/2013 179536 | c:\progra~3\browse~1\BrowserSystemEnahncerSvc.dll (671c50b0) . (…) – C:\ProgramData\Browser System Enahncer\BrowserSystemEnahncerSvc.dll
SR – | Auto 27/12/2013 182608 | c:\progra~3\winweb~1\WinWebprotectionSvc.dll (89f7ebe4) . (…) – C:\ProgramData\WinWeb protection\WinWebprotectionSvc.dll
SR – | Auto 01/01/2014 182096 | c:\progra~3\wincle~1\WincleanperformapSvc.dll (def8540c) . (…) – C:\ProgramData\Winclean performap\WincleanperformapSvc.dll
SR – | Auto 10/01/2014 502272 | (IePluginService) . (.Cherished Technololgy LIMITED.) – C:\ProgramData\IePluginService\PluginService.exe
SS – | Auto 30/12/2013 177488 | c:\progra~3\wincle~1\WincleanperformapSvc.dll (def8540c) . (…) – C:\ProgramData\Winclean performap\WincleanperformapSvc.dll
SS – | Auto 15/01/2014 146768 | (1a34a8e0) . (…) – C:\Program Files (x86)\GSSvc.dll

—\\ Scan Additionnel (O88 )
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0EA6A3F5-C0C9-AA1E-120F-6BD41323017D}] [HKLM\Software\Classes\CLSID\{0EA6A3F5-C0C9-AA1E-120F-6BD41323017D}] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0EA6A3F5-C0C9-AA1E-120F-6BD41323017D}] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0EA6A3F5-C0C9-AA1E-120F-6BD41323017D}] C:\ProgramData\AllCheapoPorIcee
C:\ProgramData\WinWeb protection
C:\ProgramData\IePluginService\PluginService.exe

Liens :

www.virustotal.com
www.herdprotect.com

Alias :

Win32/SProtector.D
a variant of Win32/SProtector.D [ESET NOD32] Generic_r.DJQ [AVG] HW32.Stranacty [Bkav FE] Trojan.Win32.SProtector

Supprimer (Remove) :

Supprimer (Remove) :
– Supprimer les logiciels de nom aléatoires via le panneau de configuration Windows,
– Modifier les pages de recherche et de démarrage de tous les navigateurs installés,
– Vider le cache des navigateurs
Nettoyer avec ZHPCleaner