Auteur Sujet: 115118.net  (Lu 15352 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25124
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
115118.net
« le: juillet 20, 2017, 14:47:32 »
Contenu republié avec la permission de Malwarebytes

115118.net est un Browser Hijacker (pirate de navigateur) qui modifie les paramètres du navigateur (page d’accueil , page de recherche, ....) afin de forcer la consultation du site ciblé et affiche aussi des publicités.


  • Paramètre cette page de démarrage, qui redirige sur une page Baidu

  • Affiche ces liens dans les Favoris

  • Paramètre un nouveau moteur de recherche par défaut










**********

Détection de 115118.net dans des rapports FRST :

Citer
HKLM-x32\...\Run: [????{] => C:\Program Files (x86)\home\gho.exe [347728 2014-07-17] ()
HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.115118.net/?772js407
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.115118.net/?772js407
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.115118.net/?772js407
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.115118.net/?772js407
SearchScopes: HKCU -> DefaultScope {EB7D113C-C3B0-B5E3-3626-035F87FFDF45} URL = hxxp://www.uc880.com/ie.htm?wd={searchTerms}&ie=utf-8
SearchScopes: HKCU -> Baidu URL = hxxp://www.uc880.com/ie.htm?wd={searchTerms}&ie=utf-8
SearchScopes: HKCU -> Google URL = hxxp://www.uc880.com/ie.htm?wd={searchTerms}&ie=utf-8
SearchScopes: HKCU -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.uc880.com/ie.htm?wd={searchTerms}&ie=utf-8
SearchScopes: HKCU -> {3887B59A-D1F6-4135-8247-48E1EC2C2EDD} URL = hxxp://www.uc880.com/ie.htm?wd={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&ie=utf-8
SearchScopes: HKCU -> {EB7D113C-C3B0-B5E3-3626-035F87FFDF45} URL = hxxp://www.uc880.com/ie.htm?wd={searchTerms}&ie=utf-8
SearchScopes: HKCU -> {F5EA8C0E-C6B5-4D60-8AFD-243026ABC33F} URL = hxxp://www.uc880.com/ie.htm?wd={searchTerms}&ie=utf-8
C:\Program Files (x86)\home



**********

Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable)


Citer
-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 9
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\Baidu, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\Google, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3887B59A-D1F6-4135-8247-48E1EC2C2EDD}, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{EB7D113C-C3B0-B5E3-3626-035F87FFDF45}, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{F5EA8C0E-C6B5-4D60-8AFD-243026ABC33F}, Delete-on-Reboot, [115], [258339],1.0.2349

Registry Value: 9
PUP.Optional.StartPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|??????, Delete-on-Reboot, [60], [415594],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\Baidu|URL, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\Google|URL, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|SUGGESTIONSURLFALLBACK, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3887B59A-D1F6-4135-8247-48E1EC2C2EDD}|URL, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{EB7D113C-C3B0-B5E3-3626-035F87FFDF45}|URL, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.ChinAd, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{F5EA8C0E-C6B5-4D60-8AFD-243026ABC33F}|URL, Delete-on-Reboot, [115], [258339],1.0.2349
PUP.Optional.StartPage, HKCU\SOFTWARE\POLICIES\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Delete-on-Reboot, [60], [415595],1.0.2349

Registry Data: 4
Hijack.StartPage.Gen, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [16643], [292512],1.0.2349
Hijack.StartPage.Gen, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|DEFAULT_PAGE_URL, Replace-on-Reboot, [16643], [292512],1.0.2349
Hijack.StartPage.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|DEFAULT_PAGE_URL, Replace-on-Reboot, [16643], [292511],1.0.2349
Hijack.StartPage.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [16643], [292511],1.0.2349

Data Stream: 0
(No malicious items detected)

Folder: 1
PUP.Optional.StartPage, C:\PROGRAM FILES (X86)\HOME, Delete-on-Reboot, [60], [415594],1.0.2349

File: 15
PUP.Optional.StartPage.Generic, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\????.URL, Delete-on-Reboot, [625], [415584],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\330LA?????.URL, Delete-on-Reboot, [625], [415587],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\XTXZ????????.URL, Delete-on-Reboot, [625], [415592],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\UC880???? ????.URL, Delete-on-Reboot, [625], [415589],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\???-?!???.URL, Delete-on-Reboot, [625], [415589],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\U?????.URL, Delete-on-Reboot, [625], [415590],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\????-????.URL, Delete-on-Reboot, [625], [415589],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\52XP WIN7????.URL, Delete-on-Reboot, [625], [415586],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\????-????.URL, Delete-on-Reboot, [625], [415589],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\115118.NET??????.URL, Delete-on-Reboot, [625], [415585],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\WIN860???? ???.URL, Delete-on-Reboot, [625], [415591],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\????????.URL, Delete-on-Reboot, [625], [415593],1.0.2349
PUP.Optional.StartPage, C:\PROGRAM FILES (X86)\HOME\GHO.EXE, Delete-on-Reboot, [60], [415594],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\26176???.URL, Delete-on-Reboot, [625], [415588],1.0.2349
PUP.Optional.StartPage.Generic, C:\USERS\{username}\FAVORITES\WIN8??????.URL, Delete-on-Reboot, [625], [415591],1.0.2349

Physical Sector: 0
(No malicious items detected)


Tutoriel d'utilisation Malwarebytes en images


Source : Removal instructions for 115118.net de Metallica - Malwarebytes Forums



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/