Security-X

Forum Security-X => Désinfections => Discussion démarrée par: anukian le août 15, 2015, 20:06:26

Titre: infection rsa-2048
Posté par: anukian le août 15, 2015, 20:06:26
Bonjour, hier il y a un truc qui a été installé sur mon pc, j' utilise Windows 8, et tous mes fichiers photos textes etc... ne sont plus lisible il y a une extension .aaa qui a été mise en place.
Je reçois des messages qui me disent de me rendre sur un site afin de récupérer une clé de cryptage. Apparemment cela serait un rançonware cryptowall que j'ai choppé. Comment puis je virer cette merde et récupérer mes fichiers sans donner de pognon a ces truands .
Merci de votre aide.
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 16, 2015, 19:40:22
Bonjour anukian,

Infection par ransomware crypteur, généralement lié à l'utilisation d'un crack de logiciel ou via une faille utilisées par des publicités infectées sur des sites de streaming ou autre.

Malheureusement, il n'y a généralement pas de solution pour les fichiers qui ont été crypté. Sauf bien entendu si tu as des sauvegardes sur un autre support.

Tout ce que l'on peut faire est de supprimer l'infection, mais cela ne te rendra pas tes fichiers.

 :AAN
Titre: Re : infection rsa-2048
Posté par: anukian le août 17, 2015, 00:09:50
Ok comment je fais pour virer ce truc sans tout formater?
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 17, 2015, 16:27:01
Re,

à faire pour un premier diagnostic :

Télécharge Farbar Recovery Scan Tool (de Farbar) sur ton Bureau.

Attention: Tu dois lancer la version compatible avec ton système : 32 ou  64bits.

Clique ici pour la version 32 bits (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/)
Clique ici pour la version 64 bits (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/)


Info : comment savoir quelle version j'utilise ? (http://windows.microsoft.com/fr-fr/windows7/find-out-32-or-64-bit)

Sous IE9 ou IE10, le filtre SmartScreen déclenche une alerte. Cliquer sur Actions puis sur Exécuter quand même

Poste les deux rapports générés.

Titre: Re : infection rsa-2048
Posté par: anukian le août 18, 2015, 01:49:23
Bonjour voici les 2 liens

http://www.cjoint.com/c/EHqsUhfA3vl

http://www.cjoint.com/c/EHqsTl6v2Ll
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 18, 2015, 14:24:16
Re,

Merci d'héberger les rapports sur le service que je demandais :
http://security-x.fr/up/

 :AAN
Titre: Re : infection rsa-2048
Posté par: anukian le août 18, 2015, 14:48:33
Voici les rapports avec les bons liens  ;)


http://up.security-x.fr/file.php?h=R576fa877030b23a180926387c8629cc6

http://up.security-x.fr/file.php?h=R10aa48c8e77dbb5254785f75ddd5158d
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 18, 2015, 15:31:52
Re,

Tu n'as pas lancé FRST depuis ton bureau, mais depuis ton navigateur, il faudra donc enregistrer FRST.exe à nouveau sur ton bureau pour la suite de la procédure.

à suivre :


1) Désinstalle les programmes suivants dans ta liste des programmes (si présents) :

Note : Si tu rencontres une erreur passe au suivant et poursuis la procédure

- Vuze Remote Toolbar v10.4 (barre d'outil lié à un adware)
- Web Companion (adware)
- Your Software Deals 1.0.0 (idem)





start
CreateRestorePoint:
CloseProcesses:
Task: {2B6F63F3-3C14-41A0-8098-F0914AADE5F2} - System32\Tasks\{3C9F9BAC-F9A8-42F6-9363-72A8C6A7BAAD} => pcalua.exe -a C:\Users\DESIRE\AppData\Local\Temp\Temp1_gdbnt.zip\Setup.exe
C:\Program Files (x86)\Lavasoft
HKLM-x32\...\Run: [MSCONFIG] => C
HKU\S-1-5-21-2209593461-3626950681-3636883461-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1380672 2015-01-23] (Lavasoft)
HKU\S-1-5-21-2209593461-3626950681-3636883461-1001\...\Run: [MSCONFIG] => C:\Users\DESIRE\AppData\Roaming\vcwlcq.exe
C:\Users\DESIRE\AppData\Roaming\vcwlcq.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sotvk.html [2015-08-13] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sotvk.txt [2015-08-13] ()
Startup: C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sotvk.html [2015-08-13] ()
Startup: C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sotvk.txt [2015-08-13] ()
Startup: C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_xchpc.html [2015-08-14] ()
Startup: C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_xchpc.txt [2015-08-14] ()
ProxyServer: [S-1-5-21-2209593461-3626950681-3636883461-1001] => http=127.0.0.1:59080;https=127.0.0.1:59080
Winsock: Catalog9-x64 01 C:\WINDOWS\system32\LavasoftTcpService64.dll [378832 2015-02-17] (Lavasoft Limited)
Winsock: Catalog9-x64 02 C:\WINDOWS\system32\LavasoftTcpService64.dll [378832 2015-02-17] (Lavasoft Limited)
Winsock: Catalog9-x64 03 C:\WINDOWS\system32\LavasoftTcpService64.dll [378832 2015-02-17] (Lavasoft Limited)
Winsock: Catalog9-x64 04 C:\WINDOWS\system32\LavasoftTcpService64.dll [378832 2015-02-17] (Lavasoft Limited)
Winsock: Catalog9-x64 15 C:\WINDOWS\system32\LavasoftTcpService64.dll [378832 2015-02-17] (Lavasoft Limited)
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mhkaekfpcppmmioggniknbnbdbcigpkk] - C:\Users\DESIRE\AppData\Local\Slick Savings\coupons.crx <non trouvé(e)>
CHR HKLM-x32\...\Chrome\Extension: [pfndaklgolladniicklehhancnlgocpp] - C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx <non trouvé(e)>
R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.1.4\LavasoftTcpService.exe [1364392 2015-01-23] (Lavasoft Limited)
R2 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [15208 2015-01-23] ()
2015-08-14 18:46 - 2015-08-14 18:46 - 02416454 _____ C:\Users\DESIRE\Desktop\RESTORE_FILES.BMP
2015-08-14 18:46 - 2015-08-14 18:46 - 00004263 _____ C:\Users\DESIRE\Desktop\RESTORE_FILES.HTML
2015-08-14 18:46 - 2015-08-14 18:46 - 00002137 _____ C:\Users\DESIRE\Desktop\RESTORE_FILES.TXT
2015-08-14 18:44 - 2015-08-14 18:44 - 00004263 _____ C:\Users\DESIRE\Desktop\restore_files_xchpc.html
2015-08-14 18:44 - 2015-08-14 18:44 - 00002137 _____ C:\Users\DESIRE\Desktop\restore_files_xchpc.txt
2015-08-14 17:31 - 2015-08-14 18:46 - 00004263 _____ C:\Users\Public\restore_files_xchpc.html
2015-08-14 17:31 - 2015-08-14 18:46 - 00004263 _____ C:\Users\Public\Downloads\restore_files_xchpc.html
2015-08-14 17:31 - 2015-08-14 18:46 - 00004263 _____ C:\Users\DESIRE\restore_files_xchpc.html
2015-08-14 17:31 - 2015-08-14 18:46 - 00002137 _____ C:\Users\Public\restore_files_xchpc.txt
2015-08-14 17:31 - 2015-08-14 18:46 - 00002137 _____ C:\Users\Public\Downloads\restore_files_xchpc.txt
2015-08-14 17:31 - 2015-08-14 18:46 - 00002137 _____ C:\Users\DESIRE\restore_files_xchpc.txt
2015-08-14 17:31 - 2015-08-14 17:31 - 00004263 _____ C:\WINDOWS\Tasks\restore_files_xchpc.html
2015-08-14 17:31 - 2015-08-14 17:31 - 00002137 _____ C:\WINDOWS\Tasks\restore_files_xchpc.txt
2015-08-14 17:28 - 2015-08-14 18:46 - 00004263 _____ C:\Users\DESIRE\Downloads\restore_files_xchpc.html
2015-08-14 17:28 - 2015-08-14 18:46 - 00004263 _____ C:\Users\DESIRE\Documents\restore_files_xchpc.html
2015-08-14 17:28 - 2015-08-14 18:46 - 00002137 _____ C:\Users\DESIRE\Downloads\restore_files_xchpc.txt
2015-08-14 17:28 - 2015-08-14 18:46 - 00002137 _____ C:\Users\DESIRE\Documents\restore_files_xchpc.txt
2015-08-14 17:01 - 2015-08-14 18:40 - 00004263 _____ C:\Users\DESIRE\AppData\Roaming\restore_files_xchpc.html
2015-08-14 17:01 - 2015-08-14 18:40 - 00004263 _____ C:\Users\DESIRE\AppData\restore_files_xchpc.html
2015-08-14 17:01 - 2015-08-14 18:40 - 00002137 _____ C:\Users\DESIRE\AppData\Roaming\restore_files_xchpc.txt
2015-08-14 17:01 - 2015-08-14 18:40 - 00002137 _____ C:\Users\DESIRE\AppData\restore_files_xchpc.txt
2015-08-14 17:00 - 2015-08-14 18:39 - 00004263 _____ C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_xchpc.html
2015-08-14 17:00 - 2015-08-14 18:39 - 00004263 _____ C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_xchpc.html
2015-08-14 17:00 - 2015-08-14 18:39 - 00002137 _____ C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_xchpc.txt
2015-08-14 17:00 - 2015-08-14 18:39 - 00002137 _____ C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_xchpc.txt
2015-08-14 16:27 - 2015-08-14 17:43 - 00004263 _____ C:\Users\DESIRE\AppData\Local\restore_files_xchpc.html
2015-08-14 16:27 - 2015-08-14 17:43 - 00002137 _____ C:\Users\DESIRE\AppData\Local\restore_files_xchpc.txt
2015-08-14 16:27 - 2015-08-14 17:33 - 00004263 _____ C:\Users\DESIRE\AppData\Local\Apps\restore_files_xchpc.html
2015-08-14 16:27 - 2015-08-14 17:33 - 00002137 _____ C:\Users\DESIRE\AppData\Local\Apps\restore_files_xchpc.txt
2015-08-14 16:18 - 2015-08-14 18:46 - 00004263 _____ C:\Users\Public\Documents\restore_files_xchpc.html
2015-08-14 16:18 - 2015-08-14 18:46 - 00002137 _____ C:\Users\Public\Documents\restore_files_xchpc.txt
2015-08-14 16:18 - 2015-08-14 16:27 - 00004263 _____ C:\ProgramData\restore_files_xchpc.html
2015-08-14 16:18 - 2015-08-14 16:27 - 00002137 _____ C:\ProgramData\restore_files_xchpc.txt
2015-08-14 16:15 - 2015-08-14 16:15 - 00000249 _____ C:\Users\DESIRE\Documents\Recovery_File_lkmwqhrwf.txt
2015-08-14 10:17 - 2015-08-14 10:17 - 00004263 _____ C:\Users\Public\Documents\restore_files_gwwyi.html
2015-08-14 10:17 - 2015-08-14 10:17 - 00004263 _____ C:\ProgramData\restore_files_gwwyi.html
2015-08-14 10:17 - 2015-08-14 10:17 - 00002137 _____ C:\Users\Public\Documents\restore_files_gwwyi.txt
2015-08-14 10:17 - 2015-08-14 10:17 - 00002137 _____ C:\ProgramData\restore_files_gwwyi.txt
2015-08-14 10:14 - 2015-08-14 10:14 - 00000249 _____ C:\Users\DESIRE\Documents\Recovery_File_dkkpdnyfe.txt
2015-08-13 23:27 - 2015-08-13 23:27 - 00265407 _____ C:\Users\DESIRE\AppData\Roaming\vcwxcg.exe
2015-08-13 23:18 - 2015-08-13 23:18 - 00004263 _____ C:\Users\DESIRE\AppData\Roaming\restore_files_sotvk.html
2015-08-13 23:18 - 2015-08-13 23:18 - 00004263 _____ C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sotvk.html
2015-08-13 23:18 - 2015-08-13 23:18 - 00004263 _____ C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sotvk.html
2015-08-13 23:18 - 2015-08-13 23:18 - 00004263 _____ C:\Users\DESIRE\AppData\restore_files_sotvk.html
2015-08-13 23:18 - 2015-08-13 23:18 - 00002137 _____ C:\Users\DESIRE\AppData\Roaming\restore_files_sotvk.txt
2015-08-13 23:18 - 2015-08-13 23:18 - 00002137 _____ C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sotvk.txt
2015-08-13 23:18 - 2015-08-13 23:18 - 00002137 _____ C:\Users\DESIRE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sotvk.txt
2015-08-13 23:18 - 2015-08-13 23:18 - 00002137 _____ C:\Users\DESIRE\AppData\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:48 - 00004263 _____ C:\Users\DESIRE\AppData\Local\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:48 - 00002137 _____ C:\Users\DESIRE\AppData\Local\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\DESIRE\AppData\Local\Apps\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default\Downloads\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default\Documents\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default.migrated\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default.migrated\Documents\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default.migrated\AppData\Roaming\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default.migrated\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default.migrated\AppData\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default.migrated\AppData\Local\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default User\Downloads\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default User\Documents\restore_files_sotvk.html
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\DESIRE\AppData\Local\Apps\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default\Downloads\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default\Documents\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default.migrated\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default.migrated\Documents\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default.migrated\AppData\Roaming\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default.migrated\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default.migrated\AppData\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default.migrated\AppData\Local\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default User\Downloads\restore_files_sotvk.txt
2015-08-13 22:27 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default User\Documents\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default\AppData\Local\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:27 - 00004263 _____ C:\Users\Default User\AppData\Local\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default\AppData\Local\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:27 - 00002137 _____ C:\Users\Default User\AppData\Local\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:24 - 00004263 _____ C:\Users\Default\Desktop\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:24 - 00004263 _____ C:\Users\Default\AppData\Roaming\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:24 - 00004263 _____ C:\Users\Default\AppData\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:24 - 00004263 _____ C:\Users\Default User\Desktop\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:24 - 00004263 _____ C:\Users\Default User\AppData\Roaming\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:24 - 00004263 _____ C:\Users\Default User\AppData\restore_files_sotvk.html
2015-08-13 22:24 - 2015-08-13 22:24 - 00002137 _____ C:\Users\Default\Desktop\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:24 - 00002137 _____ C:\Users\Default\AppData\Roaming\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:24 - 00002137 _____ C:\Users\Default\AppData\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:24 - 00002137 _____ C:\Users\Default User\Desktop\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:24 - 00002137 _____ C:\Users\Default User\AppData\Roaming\restore_files_sotvk.txt
2015-08-13 22:24 - 2015-08-13 22:24 - 00002137 _____ C:\Users\Default User\AppData\restore_files_sotvk.txt
2015-08-13 22:22 - 2015-08-13 22:22 - 00004263 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\restore_files_sotvk.html
2015-08-13 22:22 - 2015-08-13 22:22 - 00002137 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\restore_files_sotvk.txt
2015-08-13 22:21 - 2015-08-13 22:24 - 00004263 _____ C:\ProgramData\Microsoft\Windows\Start Menu\restore_files_sotvk.html
2015-08-13 22:21 - 2015-08-13 22:24 - 00002137 _____ C:\ProgramData\Microsoft\Windows\Start Menu\restore_files_sotvk.txt
2015-08-13 22:15 - 2015-08-13 22:24 - 00004263 _____ C:\ProgramData\restore_files_sotvk.html
2015-08-13 22:15 - 2015-08-13 22:24 - 00002137 _____ C:\ProgramData\restore_files_sotvk.txt
2015-08-13 22:15 - 2015-08-13 22:15 - 00004263 _____ C:\Users\Public\Documents\restore_files_sotvk.html
2015-08-13 22:15 - 2015-08-13 22:15 - 00004263 _____ C:\Users\Public\Desktop\restore_files_sotvk.html
2015-08-13 22:15 - 2015-08-13 22:15 - 00002137 _____ C:\Users\Public\Documents\restore_files_sotvk.txt
2015-08-13 22:15 - 2015-08-13 22:15 - 00002137 _____ C:\Users\Public\Desktop\restore_files_sotvk.txt
2015-08-13 22:14 - 2015-08-13 22:14 - 00004263 _____ C:\Program Files\restore_files_sotvk.html
2015-08-13 22:14 - 2015-08-13 22:14 - 00004263 _____ C:\Program Files\Common Files\restore_files_sotvk.html
2015-08-13 22:14 - 2015-08-13 22:14 - 00002137 _____ C:\Program Files\restore_files_sotvk.txt
2015-08-13 22:14 - 2015-08-13 22:14 - 00002137 _____ C:\Program Files\Common Files\restore_files_sotvk.txt
2015-08-13 22:12 - 2015-08-13 22:12 - 00004263 _____ C:\Users\restore_files_sotvk.html
2015-08-13 22:12 - 2015-08-13 22:12 - 00002137 _____ C:\Users\restore_files_sotvk.txt
2015-08-13 22:11 - 2015-08-13 22:11 - 00000249 _____ C:\Users\DESIRE\Documents\Recovery_File_ttdvxbksu.txt
2015-08-14 16:27 - 2015-02-17 22:36 - 00000000 ____D C:\Users\DESIRE\AppData\Local\Lavasoft
2015-08-14 16:24 - 2015-02-17 22:34 - 00000000 ____D C:\ProgramData\Lavasoft
C:\Program Files (x86)\Common Files\Spigot
C:\Users\DESIRE\AppData\Local\Slick Savings
RemoveProxy:
EmptyTemp:
end
/!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\



Télécharge MalwareByte's Anti-Malware (http://www.malwarebytes.org/mwb-download/) :

Titre: Re : infection rsa-2048
Posté par: anukian le août 19, 2015, 06:26:21
Voici le lien de malware :

http://up.security-x.fr/file.php?h=R6f4456f36b50be6629d28e3da0269fa7

Merci
Titre: Re&nbsp;: infection rsa-2048
Posté par: hyunkel30 le août 19, 2015, 09:20:18
Re,

Il me manque le rapport Fixlog de l'outil FRST s'il te plait.
Titre: Re : infection rsa-2048
Posté par: anukian le août 19, 2015, 14:15:27
désolé le voici

http://up.security-x.fr/file.php?h=Rcf346e4b007c3290867be31cc369c740

Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 19, 2015, 16:18:22
Re,

Ok, au niveau de l'infection, on est bon normalement.

Rencontres-tu encore des problèmes lié à l'infection ou autre, en dehors des fichiers cryptés bien entendu ?
Titre: Re : infection rsa-2048
Posté par: anukian le août 20, 2015, 16:02:34
Non pour moi il n'y a rien d'anormal, j'ai toujours les fichiers restore_files_xchp.txt et .html dans tous mes dossiers et mes fichiers sont encore cryptés mais sinon cela à l'air bon. Y a t'il une chance de les récupérer ou est-ce que je peux tous les supprimer?
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 20, 2015, 16:15:48
Re,

Normalement on a supprimé pas mal de fichier restore_files_xchp.txt et .html mais on peut continuer le ménage si tu le souhaites.
Par contre, sans te mentir, y'a peu de chance d'avoir l'occasion de récupérer les fichiers crypté ...
A la rigueur garde sur un disque externe en archive les plus important si un jour une solution de déchiffrement été trouvée ...

Pour faire la recherche des fichiers restore_files_xchp.txt et .html :

Relance FRST :

Poste le rapport généré.

Titre: Re : infection rsa-2048
Posté par: anukian le août 23, 2015, 20:26:01
Bonsoir, je n'arrive plus à poster le fichier grâce à votre mise en page de rapport car il est trop gros, y a t'il une autre solution?
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 23, 2015, 21:15:12
Re,

Sur le site d'upload tu veux dire ?
Ce serait étonnant.

Tu respectes bien la procédure expliqué dans le tutoriel pour poster ici ?
http://security-x.fr/up/
Titre: Re : infection rsa-2048
Posté par: anukian le août 24, 2015, 09:39:48
Oui la procédure est respectée mais mon fichier fait 14.4mo donc il est trop gros pour être supporté.
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 24, 2015, 09:44:27
Re,

Tu as bien seulement marqué ceci dans l'encart pour la recherche ?
Citer
restore_files_*.html;restore_files_*.txt

Titre: Re : infection rsa-2048
Posté par: anukian le août 24, 2015, 14:33:49
oui j'ai fait un copier coller
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 24, 2015, 14:47:36
Re,

Il contient combien de page le rapport search.txt ?

Tu peux juste me copier via le service d'upload la première page ?
Titre: Re : infection rsa-2048
Posté par: anukian le août 24, 2015, 15:04:32
je crois 7000 pages .

Voila le début:

http://up.security-x.fr/file.php?h=Ra51576b340aa4e6e258639f9a443e6f2
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 24, 2015, 15:26:16
Re,

Ah ouais quand même ...

Bon, faut que je réfléchisse pour voir comment on va faire le ménage là ...
Je reviens vers toi dès que possible...
Titre: Re : infection rsa-2048
Posté par: anukian le août 24, 2015, 15:33:45
Ok merci
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 24, 2015, 21:18:30
Re,

Pourrais-tu me faire passer le fichier entier via ce service :
https://www.wetransfer.com/

l'adresse mail pour me l'envoyer : hyunkel30 [a] security-x.fr
(tu attaches le tout et remplace [a] par @ )

 :AAN
Titre: Re : infection rsa-2048
Posté par: anukian le août 25, 2015, 15:36:21
bonjour, c'est envoyé.
Titre: Re : infection rsa-2048
Posté par: hyunkel30 le août 25, 2015, 17:17:12
Re,

Voilà la procédure :
(Merci à nicoolas)

$fichier="C:\Users\DESIRE\Desktop\Search2.txt"

Get-ChildItem $fichier | ForEach-Object{Get-Content $_} |  ForEach-Object{del($_)}



Redémarre le pc, puis fais de nouveau :


Relance FRST :

Poste le rapport généré.