Impossible supprimer Qone8

Résolu
Bonjour,


J'ai pourtant tout essayé, réinitialisé IE10, effectué des scan avec JRT, Malwarebytes' anti-malware, Avast, ADWcleaner, Junkware Removal Tool,... Rien n'y fait

Ci-dessous les liens obtenus avec OTL

https://forums-fec.be/upload/www/?a=d&i=5598250301 (extras)
https://forums-fec.be/upload/www/?a=d&i=0366598038 (OTL)

Merci de votre aide précieuse

28 réponses

Résumé de la discussion

Problème persistant sur Windows 7 avec Internet Explorer 10 survient malgré réinitialisation et plusieurs scans antivirus, les rapports OTL et extras évoquant une éventuelle infection. Plusieurs réponses recommandent d'exécuter SEAF.exe pour générer un log et vérifier les éléments du registre, puis d'extraire le rapport et le partager pour diagnostic initial. Des vérifications constatent des modifications de registre liées au démarrage des navigateurs, notamment StartMenuInternet et commandes Chrome/IE, et des conseils incluent la reconfiguration des paramètres du navigateur et l'analyse approfondie via OTL. Par ailleurs, des outils alternatifs et relances OTL sont proposés pour obtenir des rapports actualisés et repérer des éléments persistants non détectés par les scans standards.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    ▶ Télécharge ici :SEAF.exe de C_XX

    ▶ Lance-le, une fenêtre va s'ouvrir .

    ● Tape qone8 dans cette fenêtre

    ● Dans "[Options des fichiers]", choisis l'option MD5 pour "Calculer le checksum" et coche le bouton radio devant "Informations supplémentaires"

    ● Dans "[Options du registre]", choisis "Chercher également dans le registre"


    ▶ Clique sur "Lancer la rechercher"
    Patiente pendant la recherche.
    Une fenêtre avec un log.txt va s'afficher.
    ▶ Copie/colle ce rapport dans ta prochaine réponse.
    1
    1. Contributeur sécurité
      Salut

      ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!

      si tu as XP => double clique
      si tu as Vista ou windows 7 => clic droit "executer en tant que...."


      sur OTL.exe pour le lancer.

      ▶Copie la liste qui se trouve dans le ci-dessous,

      ▶ colle-la dans la zone sous "Personnalisation" :

       

      :OTL
      PRC - [2013/09/05 22:29:46 | 002,972,776 | ---- | M] () -- C:\Users\mgstach\AppData\Local\TotalReduc\Application\TotalReduc.exe
      MOD - [2013/09/05 22:29:46 | 002,972,776 | ---- | M] () -- C:\Users\mgstach\AppData\Local\TotalReduc\Application\TotalReduc.exe
      DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
      IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.onmylike.com/?type=hp&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B&bbb=bbb
      CHR - homepage: http://www.onmylike.com/?type=hp&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B&bbb=bbb
      O4 - Startup: C:\Users\mgstach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TotalReduc.lnk = C:\Program Files (x86)\TotalReduc\TotalReducLoader.exe ()
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B43C18A7-E7A9-4F07-90E6-43D7EBEBE52B}: NameServer = 188.121.241.253 188.121.241.254
      O20 - AppInit_DLLs: (c:\progra~3\bitguard\261673~1.238\{c16c1~1\bitguard.dll) - File not found
      [2013/09/08 10:56:42 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Extensions
      [2013/09/08 10:56:41 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\searchplugins
      [2013/09/08 10:56:15 | 000,000,000 | ---D | C] -- C:\Users\mgstach\AppData\Roaming\0T1P1I1P0C1M1T1C1N1P1C1V2XtB
      [2012/07/25 14:38:07 | 003,371,746 | ---- | C] (Brittlestar ) -- C:\Users\mgstach\TotalReducSetup.exe
      [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
      [2012/08/28 16:46:03 | 000,000,261 | ---- | M] () -- C:\user.js

      :Reg
      [-HKEY_CURRENT_USER\Software\USyndication]
      [-HKEY_CURRENT_USER\Software\usyndication.com]
      [-HKEY_LOCAL_MACHINE\Software\qone8Software]

      :commands
      [emptytemp]


      ▶ Clique sur "Correction" pour lancer la suppression.

      ▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail apres le redemarrage.

      0
      1. Ca ne fonctionne toujours pas

        rapport
        https://forums-fec.be/upload/www/?a=d&i=9069601994
        0
        1. Contributeur sécurité
          normal j'sais pas ce que t'as fichu ...

          recommence en foirant pas ton copier/coller
          0
          1. j'comprends pas, fonctionne toujours pas

            Au secours !!!!

            lien
            https://forums-fec.be/upload/www/?a=d&i=9974951872
            0
            1. trompé de lien je crois

              Voila le dernier rapport et ça fonctionne toujours pas

              https://forums-fec.be/upload/www/?a=d&i=7665665566
              0
              1. Rien à faire

                N'as tu pas une autre solution pour m'aider, je ne comprends pas, j'y ai passé le WE et la journée. j'ai tout essayé

                Merci de ton aide
                0
                1. Ci dessous le rapport

                  merci de ton aide

                  1. ========================= SEAF 1.0.1.0 - C_XX
                  2.
                  3. Commencé à: 20:38:45 le 30/09/2013
                  4.
                  5. Valeur(s) recherchée(s):
                  6. qone8
                  7.
                  8. Légende: TC => Date de création, TM => Date de modification, DA => Dernier accès
                  9.
                  10. (!) --- Calcul du Hash "MD5"
                  11. (!) --- Informations supplémentaires
                  12. (!) --- Recherche registre
                  13.
                  14. ====== Fichier(s) ======
                  15.
                  16.
                  17. "C:\Users\mgstach\AppData\Local\Microsoft\Internet Explorer\DOMStore\YPPA424E\start.qone8[1].xml" [ NOT_CONTENT_INDEXED|ARCHIVE | 13 o ]
                  18. TC: 30/09/2013,15:00:07 | TM: 30/09/2013,15:00:07 | DA: 30/09/2013,15:00:07
                  19.
                  20. Hash MD5: C1DDEA3EF6BBEF3E7060A1A9AD89E4C5
                  21.
                  22.
                  23. =========================
                  24.
                  25.
                  26. "C:\Users\mgstach\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3IBORJYQ\start_qone8_com[1].htm" [ NOT_CONTENT_INDEXED|ARCHIVE | 10 Ko ]
                  27. TC: 30/09/2013,19:45:51 | TM: 30/09/2013,19:45:51 | DA: 30/09/2013,19:45:51
                  28.
                  29. Hash MD5: 43850F81FB26B09F60A4DE4674DDC64C
                  30.
                  31.
                  32. =========================
                  33.
                  34.
                  35. "C:\Users\mgstach\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZTK12OEN\affich-28809427-impossible-supprimer-qone8[1].htm" [ NOT_CONTENT_INDEXED|ARCHIVE | 62 Ko ]
                  36. TC: 30/09/2013,19:46:35 | TM: 30/09/2013,19:46:35 | DA: 30/09/2013,19:46:35
                  37.
                  38. Hash MD5: 9071CA78B86D60AD84AB5A1710D4F961
                  39.
                  40.
                  41. =========================
                  42.
                  43.
                  44. "C:\Users\mgstach\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\ZXIH3OZC\start.qone8[1].xml" [ NOT_CONTENT_INDEXED|ARCHIVE | 13 o ]
                  45. TC: 30/09/2013,14:46:52 | TM: 30/09/2013,19:45:52 | DA: 30/09/2013,19:45:52
                  46.
                  47. Hash MD5: C1DDEA3EF6BBEF3E7060A1A9AD89E4C5
                  48.
                  49.
                  50. =========================
                  51.
                  52.
                  53.
                  54. ====== Entrée(s) du registre ======
                  55.
                  56.
                  57. [HKLM\Software\Clients\StartMenuInternet\Google Chrome\shell\open\command]
                  58. ""=""C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://start.qone8.com/?type=sc&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B" (REG_SZ)
                  59.
                  60. [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]
                  61. ""="C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B" (REG_SZ)
                  62.
                  63. =========================
                  64.
                  65. Fin à: 20:43:54 le 30/09/2013
                  66. 665873 Éléments analysés
                  67.
                  68. =========================
                  69. E.O.F
                  0
                  1. Contributeur sécurité
                    Han je vois :)

                    Lance ça : http://www.security-helpzone.com/Tools/g3n/Shortcut_Module.exe

                    Poste le rapport
                    0
                    1. Si ca te parle tout ça, chapeau !!!! ;-)

                      ¤¤¤¤¤¤¤¤¤¤ | Shortcut_Module 27.09.2013 - g3n-h@ckm@n

                      21:29:14 - 30/09/2013

                      Disinfected : C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk : C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (hxxp://start.qone8.com/?type=sc&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B)
                      Disinfected : C:\Users\mgstach\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk : C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (hxxp://start.qone8.com/?type=sc&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B)
                      Disinfected : C:\Users\mgstach\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk : C:\Program Files (x86)\Internet Explorer\iexplore.exe (hxxp://start.qone8.com/?type=sc&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B)
                      Disinfected : C:\Users\mgstach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://start.qone8.com/?type=sc&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B)
                      Disinfected : C:\Users\mgstach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://start.qone8.com/?type=sc&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B)
                      Disinfected : C:\Users\mgstach\Desktop\Internet Explorer.lnk : C:\Program Files (x86)\Internet Explorer\iexplore.exe (hxxp://start.qone8.com/?type=sc&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B)
                      Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk : C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (hxxp://start.qone8.com/?type=sc&ts=1380356444&from=air&uid=VB0250EAVER_Z2AFGL3B)
                      0
                      1. Contributeur sécurité
                        ▶ Télécharge ici :OTL

                        ▶ Fais un double clic sur l'icône pour le lancer (clic droit executer en tant qu'administrateur sous Vista, Windows 7 ou Windows 8). Vérifier que toutes les autres fenêtres sont fermées afin qu'il s'exécute sans interruption.

                        ▶ Copie et colle le contenu de ce qui suit en gras dans la partie inférieure d'OTL "Personnalisation"


                        :reg
                        [HKLM\Software\Clients\StartMenuInternet\Google Chrome\shell\open\command]
                        ""=-
                        ""=REG_SZ:""C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"

                        [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]
                        ""=-
                        ""=REG_SZ:""C:\Program Files\Internet Explorer\iexplore.exe"


                        ▶ Clique sur "Correction" pour lancer la suppression.

                        ▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail
                        0
                        1. ========== REGISTRY ==========
                          Registry value HKEY_LOCAL_MACHINE\Software\Clients\StartMenuInternet\Google Chrome\shell\open\command\\ deleted successfully.
                          HKLM\Software\Clients\StartMenuInternet\Google Chrome\shell\open\command\\""|REG_SZ:""C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" /E :invalid edit format. Invalid data type.
                          Registry value HKEY_LOCAL_MACHINE\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\ deleted successfully.
                          HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\""|REG_SZ:""C:\Program Files\Internet Explorer\iexplore.exe" /E :invalid edit format. Invalid data type.

                          OTL by OldTimer - Version 3.2.69.0 log created on 09302013_230027
                          0
                          1. Contributeur sécurité
                            Mmmmmmmmmmmmmh

                            Refais avec ça voir :

                            :OTL
                            [HKLM\Software\Clients\StartMenuInternet\Google Chrome\shell\open\command]
                            ""=""C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"

                            [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]
                            ""=""C:\Program Files\Internet Explorer\iexplore.exe"

                            0
                            1. ========== OTL ==========
                              File LM\Software\Clients\StartMenuInternet\Google Chrome\shell\open\command] not found.
                              File LM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command] not found.

                              OTL by OldTimer - Version 3.2.69.0 log created on 09302013_230606
                              0
                              1. Contributeur sécurité
                                Ah merde excuse ^^
                                Je fatigue :p

                                Comme ceci ça ira mieux :

                                :REG
                                [HKLM\Software\Clients\StartMenuInternet\Google Chrome\shell\open\command]
                                ""=""C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"

                                [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]
                                ""=""C:\Program Files\Internet Explorer\iexplore.exe"
                                0
                                1. je veux bien te croire que tu fatigues...

                                  ========== REGISTRY ==========
                                  HKLM\Software\Clients\StartMenuInternet\Google Chrome\shell\open\command\\""|""C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" /E : value set successfully!
                                  HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\""|""C:\Program Files\Internet Explorer\iexplore.exe" /E : value set successfully!

                                  OTL by OldTimer - Version 3.2.69.0 log created on 09302013_231558
                                  0
                                  1. Contributeur sécurité
                                    Ah ben tout de suite voilà qui est mieux ^^

                                    Normalement le problème est réglé, vérifie.
                                    0
                                    1. Non, toujours pas ni Chrome ni IE. J'ai pas redémarrer mais ça marche pas :-(
                                      0
                                      1. Contributeur sécurité
                                        Relance OTL,

                                        ▶ Clique ici pour voir la configuration

                                        ▶ Copie et colle le contenu de ce qui suit en gras dans la partie inférieure d'OTL "Personnalisation"


                                        HKCU\Software
                                        HKLM\Software
                                        %Homedrive%\*
                                        %Homedrive%\*.
                                        %Userprofile%\*
                                        %Userprofile%\*.
                                        %Allusersprofile%\*
                                        %Allusersprofile%\*.
                                        %localappdata%\*
                                        %localappdata%\*.
                                        %Userprofile%\Local Settings\Application Data\*
                                        %Userprofile%\Local Settings\Application Data\*.
                                        %programFiles%\*
                                        %programFiles%\*.
                                        %Systemroot%\Temp\*.exe /s
                                        %systemroot%\system32\*.dll /lockedfiles
                                        %systemroot%\system32\*.exe /lockedfiles
                                        %systemroot%\system32\*.in*
                                        %systemroot%\Tasks\*
                                        %systemroot%\Tasks\*.
                                        %systemroot%\system32\Tasks\*
                                        %systemroot%\system32\Tasks\*.
                                        %systemroot%\system32\drivers\*.sy* /lockedfiles
                                        %systemroot%\system32\config\*.exe /s
                                        %Systemroot%\ServiceProfiles\*.exe /s
                                        %systemroot%\system32\*.sys
                                        %temp%\*.exe /s
                                        %ALLUSERSPROFILE%\Application Data\*.exe /s
                                        %ALLUSERSPROFILE%\Application Data\*.
                                        %APPDATA%\*.exe /s
                                        %LocalAppData%\*
                                        %LocalAppData%\*.
                                        %SYSTEMDRIVE%\*.*
                                        /md5start
                                        explorer.exe
                                        winlogon.exe
                                        userinit.exe
                                        svchost.exe
                                        services.exe
                                        winsock.*
                                        /md5stop
                                        msconfig
                                        netsvcs
                                        BASESERVICES
                                        safebootminimal
                                        safebootnetwork
                                        CREATERESTOREPOINT
                                        SAVEMBR:0
                                        HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
                                        HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command
                                        HKLM\Software\Clients\StartMenuInternet\Google Chrome\shell\open\command
                                        dir "%Homedrive%\*" /S /A:L /C


                                        ▶ Clic sur Analyse.

                                        A la fin du scan, 2 Bloc-Notes vont s'ouvrir avec les rapports (OTL.txt et extras.txt).

                                        NE PAS COPIER/COLLER LE RAPPORT ICI - LIRE JUSQU'AU BOUT

                                        Ces fichiers se trouvent à côté de l'exécutable OTL.exe

                                        héberge OTL.txt et extra.txt sur FEC Upload et donne les liens obtenus en échange

                                        NE PAS COPIER/COLLER LE LIEN DE SUPPRESSION, CONSERVE-LE SI TU DESIRE ENSUITE SUPPRIMER LES RAPPORTS DE LA BASE DE DONNEES FEC
                                        0
                                        • 1
                                        • 2