Re: attaque d'un trojan dans mon système informatique
Posté : 11 mars 2009, 13:38
J'ai suprimé tous les cracks que j'ai trouvé, j'ai lancé l'option 2 de toolbar et j'ai remarqué que j'en avais oublié mais lorsque j'ai voulu les suprimer, je ne trouve pas les 2 premiers, le troisième est suprimé
Voici le rapport avant les dernières suppressions (dois je le relancer ?) :
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU 2140 @ 1.60GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : isabelle ( Not Administrator ! )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1290 [VPS 081122-0] 4.8.1290 (Activated)
C:\ (Local Disk) - NTFS - Total:225 Go (Free:16 Go)
D:\ (Local Disk) - NTFS - Total:7 Go (Free:1 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
K:\ (Local Disk) - NTFS - Total:232 Go (Free:81 Go)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 11/03/2009|13:23 )
[ UAC => 1 ]
-----------\\ SUPPRESSION
Echec ! - C:\Program Files\AskTBar\bar
Echec ! - C:\Program Files\AskTBar\SrchAstt
Echec ! - C:\Program Files\AskTBar\bar\1.bin
Echec ! - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
Supprime! - C:\Users\isabelle\AppData\Roaming\MICROS~1\Windows\Cookies\isabelle@mysearch[1].txt
Supprime! - C:\Windows\iun6002.exe
Echec ! - C:\Program Files\AskTBar
Supprime! - C:\ProgramData\GamesBar
-----------\\ DEUXIEME PASSAGE
Echec ! - C:\Program Files\AskTBar\bar
Echec ! - C:\Program Files\AskTBar\SrchAstt
Echec ! - C:\Program Files\AskTBar\bar\1.bin
Echec ! - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
Echec ! - C:\Program Files\AskTBar
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskTBar
C:\Program Files\AskTBar\bar
C:\Program Files\AskTBar\SrchAstt
C:\Program Files\AskTBar\bar\1.bin
C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
C:\Program Files\AskTBar\SrchAstt\1.bin
C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
C:\Users\isabelle\AppData\Roaming\MICROS~1\Windows\Cookies\isabelle@mysearch[3].txt
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://fr.msn.com/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
"Url"="http://go.microsoft.com/fwlink/?LinkId=75720"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/"
"Default_Page_URL"="http://fr.yahoo.com"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
--------------------\\ Recherche d'autres infections
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
DhcpNameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{5C9BB10B-0941-4BF3-AA9E-A86F67C059F9}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
DhcpNameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\..\{5C9BB10B-0941-4BF3-AA9E-A86F67C059F9}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
DhcpNameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{5C9BB10B-0941-4BF3-AA9E-A86F67C059F9}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
==> WAREOUT <==
--------------------\\ Cracks & Keygens ..
C:\Users\isabelle\AppData\Roaming\Microsoft\Windows\Recent\Luxor 3 - Jeu PC + Crack.lnk
C:\Users\isabelle\AppData\Roaming\Microsoft\Windows\Recent\psp10 crack.lnk
C:\Users\isabelle\Pictures\cours PSP\Laetitia\Section 2 Cours (photos d'origine)\Cours 1\Filtre\FM tile tool\Fm tile tool\crackfmtool.zip
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 10/03/2009|19:25 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 11/03/2009|13:26 - Option : [2]
-----------\\ Fin du rapport a 13:26:59,82
Voici le rapport avant les dernières suppressions (dois je le relancer ?) :
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU 2140 @ 1.60GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : isabelle ( Not Administrator ! )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1290 [VPS 081122-0] 4.8.1290 (Activated)
C:\ (Local Disk) - NTFS - Total:225 Go (Free:16 Go)
D:\ (Local Disk) - NTFS - Total:7 Go (Free:1 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
K:\ (Local Disk) - NTFS - Total:232 Go (Free:81 Go)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 11/03/2009|13:23 )
[ UAC => 1 ]
-----------\\ SUPPRESSION
Echec ! - C:\Program Files\AskTBar\bar
Echec ! - C:\Program Files\AskTBar\SrchAstt
Echec ! - C:\Program Files\AskTBar\bar\1.bin
Echec ! - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
Supprime! - C:\Users\isabelle\AppData\Roaming\MICROS~1\Windows\Cookies\isabelle@mysearch[1].txt
Supprime! - C:\Windows\iun6002.exe
Echec ! - C:\Program Files\AskTBar
Supprime! - C:\ProgramData\GamesBar
-----------\\ DEUXIEME PASSAGE
Echec ! - C:\Program Files\AskTBar\bar
Echec ! - C:\Program Files\AskTBar\SrchAstt
Echec ! - C:\Program Files\AskTBar\bar\1.bin
Echec ! - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin
Echec ! - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
Echec ! - C:\Program Files\AskTBar
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskTBar
C:\Program Files\AskTBar\bar
C:\Program Files\AskTBar\SrchAstt
C:\Program Files\AskTBar\bar\1.bin
C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
C:\Program Files\AskTBar\SrchAstt\1.bin
C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
C:\Users\isabelle\AppData\Roaming\MICROS~1\Windows\Cookies\isabelle@mysearch[3].txt
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://fr.msn.com/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
"Url"="http://go.microsoft.com/fwlink/?LinkId=75720"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/"
"Default_Page_URL"="http://fr.yahoo.com"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
--------------------\\ Recherche d'autres infections
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
DhcpNameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{5C9BB10B-0941-4BF3-AA9E-A86F67C059F9}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
DhcpNameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\..\{5C9BB10B-0941-4BF3-AA9E-A86F67C059F9}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{00073901-D3B3-426E-A26C-D041D5C1C693}]
DhcpNameServer REG_SZ 85.255.114.76,85.255.112.81
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{5C9BB10B-0941-4BF3-AA9E-A86F67C059F9}]
NameServer REG_SZ 85.255.114.76,85.255.112.81
==> WAREOUT <==
--------------------\\ Cracks & Keygens ..
C:\Users\isabelle\AppData\Roaming\Microsoft\Windows\Recent\Luxor 3 - Jeu PC + Crack.lnk
C:\Users\isabelle\AppData\Roaming\Microsoft\Windows\Recent\psp10 crack.lnk
C:\Users\isabelle\Pictures\cours PSP\Laetitia\Section 2 Cours (photos d'origine)\Cours 1\Filtre\FM tile tool\Fm tile tool\crackfmtool.zip
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 10/03/2009|19:25 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 11/03/2009|13:26 - Option : [2]
-----------\\ Fin du rapport a 13:26:59,82