[..] est disponible comme Giveaway of the day! Vous avez [..] pour le télécharger et l’installer.
Ce logiciel était disponible gratuitement le [..]. Il n’est plus disponible. Vous pouvez télécharger sa version d’essai à l’adresse [..].
Name: Christmas Eve 3D ScreensaverIl se trouve qu'en jouant avec la variable id, il y est la possibilité de télécharger des logiciels de jours passés, et ceci ce révèle exact !
URL: http://fr.giveawayoftheday.com/download/?id=7719
Name: Flip AlbumLe téléchargement s'exécute, ce n'est pas magique ?
URL: http://fr.giveawayoftheday.com/download/?id=7718
# Name: Give Away Of The Day Downloader
# Author: Xartrick
# Date: 18/12/2011
# Home: http://xartrick.blogspot.com/
from sys import argv
import urllib2
def _GetBetween(sString, sStart, sEnd):
sSplit = sString.split(sStart)
sSplit = sSplit[1].split(sEnd)
return sSplit[0]
print("+---------------------------------+")
print("| Give Away Of The Day Downloader |")
print("+--------+------------------------+")
print("| Author | Xartrick |")
print("| Home | xartrick.blogspot.com |")
print("+--------+------------------------+")
print("| Tapz is legion |")
print("+---------------------------------+")
if (len(argv) != 2):
print("\nUsage: %s <url>" % (argv[0]))
else:
sURL = argv[1]
oURLOpen = urllib2.urlopen(sURL)
sSource = oURLOpen.read()
sID = _GetBetween(sSource, "p=", "'")
sLink = "http://fr.giveawayoftheday.com/download/?id=" + sID
print("\nURL: %s" % (sLink))
C:\Documents and Settings\Xartrick\Bureau>"GAOTD Downloader.py" http://fr.giveawayoftheday.com/flip-album/
+---------------------------------+
| Give Away Of The Day Downloader |
+--------+------------------------+
| Author | Xartrick |
| Home | xartrick.blogspot.com |
+--------+------------------------+
| Tapz is legion |
+---------------------------------+
URL: http://fr.giveawayoftheday.com/download/?id=7718Pour télécharger un programme, un lien nous est fourni, voici en exemple celui d'aujourd'hui ...Excuse moi, j'ai du rater un épisode, l'id des fichiers ne changent pas de jour en jour apparemment ...
Name: Christmas Eve 3D Screensaver
URL: http://fr.giveawayoftheday.com/download/?id=7719
Il se trouve qu'en jouant avec la variable id, il y est la possibilité de télécharger des logiciels de jours passés, et ceci ce révèle exact !
Name: Flip Album
URL: http://fr.giveawayoftheday.com/download/?id=7718
Le téléchargement s'exécute, ce n'est pas magique ?
C'est justement là que je penses que cela ne passe pas, il faut simplement que vous (la communauté) vérifié cela car je n'aime pas trop ce type de programme :p.Bien que passionnés, ont est tous bénévoles :) ... puis tu fais aussi partie de "la communauté" ... Merci de relever celui ci ...
On peut qualifié cela de faille à partir du moment où le site ne veut pas que nous téléchargeons ces fichiers :).
Le seul soucis reste à savoir si le logiciel fonctionne correctement, ceci est à vous de tester, je n'ai pas besoin de m'encombrer de ce type de logiciel.Après avoir décompressé l'archive téléchargée("?id=7719") on voit apparaître deux fichiers : "Setup.exe" &
InstallationAntivirFree repère lui 4(2+2) fichiers : (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fpix.toile-libre.org%2Fupload%2Fthumb%2F1324252824.png&hash=9d06dc6e7838557d27ba70d1acfc29d819e385ab) (http://pix.toile-libre.org/?img=1324252824.png) - (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fpix.toile-libre.org%2Fupload%2Fthumb%2F1324252563.png&hash=c5d21761b904426de697eba572eaba2e9a5fccc9) (http://pix.toile-libre.org/?img=1324252563.png)
Unzip the package you`ve downloaded and run Setup.exe which is included in the package, to
install and activate the software.
You have to install it before the Giveaway offer for the software is over.
Terms and conditions
Please note that the software you download and install during
the Giveaway period comes with the following important limitations:
1) No free technical support
2) No free upgrades to future versions
3) Strictly non-commercial usage
. . : Cf. pièce jointe : "Christmas.txt" : . .
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Version de la base de données: 8394
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
19/12/2011 0:16:28
mbam-log-2011-12-19 (00-16-28).txt
Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 186421
Temps écoulé: 23 minute(s), 28 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 16
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\HomePage (PUM.Hijack.HomePageControl) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP2\A0000010.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP2\A0000011.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP2\A0000012.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001446.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001431.scr (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001433.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001434.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001435.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001437.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001438.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001439.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001440.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001441.SCR (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001443.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001444.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001445.EXE (PUP.FunWebProducts) -> Quarantined and deleted successfully.
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Astro Gemini Software]
"Order"=hex:08,00,00,00,02,00,00,00,a2,00,00,00,01,00,00,00,01,00,00,00,96,\
00,00,00,00,00,00,00,88,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,76,00,\
31,00,00,00,00,00,92,3f,4d,ad,10,00,43,48,52,49,53,54,7e,31,00,00,50,00,03,\
00,04,00,ef,be,92,3f,4d,ad,92,3f,4d,ad,14,00,00,00,43,00,68,00,72,00,69,00,\
73,00,74,00,6d,00,61,00,73,00,20,00,45,00,76,00,65,00,20,00,33,00,44,00,20,\
00,53,00,63,00,72,00,65,00,65,00,6e,00,73,00,61,00,76,00,65,00,72,00,00,00,\
18,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,18,00,00,00,00,00,00,00,00,00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Astro Gemini Software\Christmas Eve 3D Screensaver]
"Order"=hex:08,00,00,00,02,00,00,00,6e,02,00,00,01,00,00,00,04,00,00,00,ac,\
00,00,00,00,00,00,00,9e,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,8c,00,\
32,00,cc,02,00,00,92,3f,4d,ad,20,00,4f,50,45,4e,43,48,7e,31,2e,4c,4e,4b,00,\
00,62,00,03,00,04,00,ef,be,92,3f,4d,ad,92,3f,4d,ad,14,00,00,00,4f,00,70,00,\
65,00,6e,00,20,00,43,00,68,00,72,00,69,00,73,00,74,00,6d,00,61,00,73,00,20,\
00,45,00,76,00,65,00,20,00,33,00,44,00,20,00,53,00,63,00,72,00,65,00,65,00,\
6e,00,73,00,61,00,76,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,\
00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,78,00,00,00,\
01,00,00,00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,00,83,\
03,00,00,92,3f,4d,ad,20,00,52,45,41,44,4d,45,7e,31,2e,4c,4e,4b,00,00,2e,00,\
03,00,04,00,ef,be,92,3f,4d,ad,92,3f,4d,ad,14,00,00,00,52,00,65,00,61,00,64,\
00,20,00,4d,00,65,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,\
ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,b6,00,00,00,02,00,00,00,a8,\
00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,96,00,32,00,88,03,00,00,92,3f,\
4d,ad,20,00,55,4e,49,4e,53,54,7e,31,2e,4c,4e,4b,00,00,6c,00,03,00,04,00,ef,\
be,92,3f,4d,ad,92,3f,4d,ad,14,00,00,00,55,00,6e,00,69,00,6e,00,73,00,74,00,\
61,00,6c,00,6c,00,20,00,43,00,68,00,72,00,69,00,73,00,74,00,6d,00,61,00,73,\
00,20,00,45,00,76,00,65,00,20,00,33,00,44,00,20,00,53,00,63,00,72,00,65,00,\
65,00,6e,00,73,00,61,00,76,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,\
00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,88,00,\
00,00,03,00,00,00,7a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,68,00,32,\
00,31,07,00,00,92,3f,4d,ad,20,00,56,49,53,49,54,48,7e,31,2e,4c,4e,4b,00,00,\
3e,00,03,00,04,00,ef,be,92,3f,4d,ad,92,3f,4d,ad,14,00,00,00,56,00,69,00,73,\
00,69,00,74,00,20,00,48,00,6f,00,6d,00,65,00,20,00,50,00,61,00,67,00,65,00,\
2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,\
00,00,00,00,00,00,00,00,00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Astro Gemini Software\Christmas Eve 3D Screensaver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\WINDOWS\\system32\\Christmas Eve 3D Screensaver.scr"="Christmas Eve 3D Screensaver"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Astro Gemini Software\\Christmas Eve 3D Screensaver\\unins000.exe"="Setup/Uninstall"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\WINDOWS\\system32\\CHRIST~1.SCR"="CHRIST~1"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Astro Gemini Software\\Christmas Eve 3D Screensaver\\unins000.exe"="Setup/Uninstall"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Multi\\LOCALS~1\\Temp\\_iu14D2N.tmp"="Setup/Uninstall"
Bonjour Xartrick, soit le bienvenu sur Security-X :)
Excuse moi, j'ai du rater un épisode, l'id des fichiers ne changent pas de jour en jour apparemment ...
sont ils disponibles dans le code source de la page spécifique ou tu les avais noté auparavant ?
(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fpix.toile-libre.org%2Fupload%2Fimg%2F1324251290.png&hash=71f563a6af216e7ed514edde81dbfcad0af1dac1) (http://pix.toile-libre.org/?img=1324251290.png)
Effectivement, il existe de nombreuses manières de s'approprier la db sql notamment par l'exploit
de champ de texte ... Le Php n'est pas une science exacte/infaillible .. Le cms WordPress non plus :NNN
bref comment as-tu fais exactement ?
Bien que passionnés, ont est tous bénévoles :) ... puis tu fais aussi partie de "la communauté" ... Merci de relever celui ci ...
Il y a tellement de nouveau site/domaines pourris ou fake qui pullulent tous les jours que mêmes les éditeurs d'antivirus ont du mal a suivre ;)CiterLe seul soucis reste à savoir si le logiciel fonctionne correctement, ceci est à vous de tester, je n'ai pas besoin de m'encombrer de ce type de logiciel.Après avoir décompressé l'archive téléchargée("?id=7719") on voit apparaître deux fichiers : "Setup.exe" &Citation de: Readme.txtInstallationAntivirFree repère lui 4(2+2) fichiers : (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fpix.toile-libre.org%2Fupload%2Fthumb%2F1324252824.png&hash=9d06dc6e7838557d27ba70d1acfc29d819e385ab) (http://pix.toile-libre.org/?img=1324252824.png) - (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fpix.toile-libre.org%2Fupload%2Fthumb%2F1324252563.png&hash=c5d21761b904426de697eba572eaba2e9a5fccc9) (http://pix.toile-libre.org/?img=1324252563.png)
Unzip the package you`ve downloaded and run Setup.exe which is included in the package, to
install and activate the software.
You have to install it before the Giveaway offer for the software is over.
Terms and conditions
Please note that the software you download and install during
the Giveaway period comes with the following important limitations:
1) No free technical support
2) No free upgrades to future versions
3) Strictly non-commercial usage
Bon il n'a pas la cote sur leur site avec 74% de décus :D .. Je l'ai essayé et il ne
fonctionne pas sur une VB XP Home ... C'est même un peu pourri sur les bords ..:
(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fpix.toile-libre.org%2Fupload%2Fimg%2F1324253293.png&hash=3f7b8499cd53d190f06230ff2d488c7b40965b07) (http://pix.toile-libre.org/?img=1324253293.png) - (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fpix.toile-libre.org%2Fupload%2Fimg%2F1324253350.png&hash=caa7799858644060d1e83875ea5cddc310a848c9) (http://pix.toile-libre.org/?img=1324253350.png) *** - (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fpix.toile-libre.org%2Fupload%2Fimg%2F1324253447.png&hash=8acf17bcd61f51aaee210f5b8dbecbc851ff7d32) (http://pix.toile-libre.org/?img=1324253447.png)
(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fpix.toile-libre.org%2Fupload%2Fthumb%2F1324252490.png&hash=303185bce1ea3ab61f616380dfcc70c50064e76f) (http://pix.toile-libre.org/?img=1324252490.png) - (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fpix.toile-libre.org%2Fupload%2Fthumb%2F1324252237.png&hash=ddd3fdae9cb5b9c5cede48a3f48780334a145232) (http://pix.toile-libre.org/?img=1324252237.png) = FAIL & Message d'erreur Windows *** ...Citation de: Résultat RegShot. . : Cf. pièce jointe : "Christmas.txt" : . .Citation de: Rapport MalwarebytesMalwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Version de la base de données: 8394
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
19/12/2011 0:16:28
mbam-log-2011-12-19 (00-16-28).txt
Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 186421
Temps écoulé: 23 minute(s), 28 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 16
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\HomePage (PUM.Hijack.HomePageControl) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP2\A0000010.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP2\A0000011.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP2\A0000012.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001446.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001431.scr (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001433.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001434.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001435.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001437.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001438.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001439.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001440.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001441.SCR (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001443.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001444.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{2dd6c940-cfe1-45ac-8373-d08999d3e04b}\RP6\A0001445.EXE (PUP.FunWebProducts) -> Quarantined and deleted successfully.Citation de: Nettoyage RegistreWindows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Astro Gemini Software]
"Order"=hex:08,00,00,00,02,00,00,00,a2,00,00,00,01,00,00,00,01,00,00,00,96,\
00,00,00,00,00,00,00,88,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,76,00,\
31,00,00,00,00,00,92,3f,4d,ad,10,00,43,48,52,49,53,54,7e,31,00,00,50,00,03,\
00,04,00,ef,be,92,3f,4d,ad,92,3f,4d,ad,14,00,00,00,43,00,68,00,72,00,69,00,\
73,00,74,00,6d,00,61,00,73,00,20,00,45,00,76,00,65,00,20,00,33,00,44,00,20,\
00,53,00,63,00,72,00,65,00,65,00,6e,00,73,00,61,00,76,00,65,00,72,00,00,00,\
18,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,18,00,00,00,00,00,00,00,00,00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Astro Gemini Software\Christmas Eve 3D Screensaver]
"Order"=hex:08,00,00,00,02,00,00,00,6e,02,00,00,01,00,00,00,04,00,00,00,ac,\
00,00,00,00,00,00,00,9e,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,8c,00,\
32,00,cc,02,00,00,92,3f,4d,ad,20,00,4f,50,45,4e,43,48,7e,31,2e,4c,4e,4b,00,\
00,62,00,03,00,04,00,ef,be,92,3f,4d,ad,92,3f,4d,ad,14,00,00,00,4f,00,70,00,\
65,00,6e,00,20,00,43,00,68,00,72,00,69,00,73,00,74,00,6d,00,61,00,73,00,20,\
00,45,00,76,00,65,00,20,00,33,00,44,00,20,00,53,00,63,00,72,00,65,00,65,00,\
6e,00,73,00,61,00,76,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,\
00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,78,00,00,00,\
01,00,00,00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,00,83,\
03,00,00,92,3f,4d,ad,20,00,52,45,41,44,4d,45,7e,31,2e,4c,4e,4b,00,00,2e,00,\
03,00,04,00,ef,be,92,3f,4d,ad,92,3f,4d,ad,14,00,00,00,52,00,65,00,61,00,64,\
00,20,00,4d,00,65,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,\
ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,b6,00,00,00,02,00,00,00,a8,\
00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,96,00,32,00,88,03,00,00,92,3f,\
4d,ad,20,00,55,4e,49,4e,53,54,7e,31,2e,4c,4e,4b,00,00,6c,00,03,00,04,00,ef,\
be,92,3f,4d,ad,92,3f,4d,ad,14,00,00,00,55,00,6e,00,69,00,6e,00,73,00,74,00,\
61,00,6c,00,6c,00,20,00,43,00,68,00,72,00,69,00,73,00,74,00,6d,00,61,00,73,\
00,20,00,45,00,76,00,65,00,20,00,33,00,44,00,20,00,53,00,63,00,72,00,65,00,\
65,00,6e,00,73,00,61,00,76,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,\
00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,88,00,\
00,00,03,00,00,00,7a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,68,00,32,\
00,31,07,00,00,92,3f,4d,ad,20,00,56,49,53,49,54,48,7e,31,2e,4c,4e,4b,00,00,\
3e,00,03,00,04,00,ef,be,92,3f,4d,ad,92,3f,4d,ad,14,00,00,00,56,00,69,00,73,\
00,69,00,74,00,20,00,48,00,6f,00,6d,00,65,00,20,00,50,00,61,00,67,00,65,00,\
2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,\
00,00,00,00,00,00,00,00,00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Astro Gemini Software\Christmas Eve 3D Screensaver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\WINDOWS\\system32\\Christmas Eve 3D Screensaver.scr"="Christmas Eve 3D Screensaver"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Astro Gemini Software\\Christmas Eve 3D Screensaver\\unins000.exe"="Setup/Uninstall"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\WINDOWS\\system32\\CHRIST~1.SCR"="CHRIST~1"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Astro Gemini Software\\Christmas Eve 3D Screensaver\\unins000.exe"="Setup/Uninstall"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Multi\\LOCALS~1\\Temp\\_iu14D2N.tmp"="Setup/Uninstall"
Thanks pour l'outil ! Sympa les articles sur ton site, n'hésites pas à partager des info's sur
le reverse engineering ou pour récuperer des données d'un malware ... D'avance merci ...
De rien c'est normal :)Bonjour Xartrick, soit le bienvenu sur Security-X :)Merci à toi, c'est très sympa.
OK thanks, mais donc c'est bien grâce à ce bout de code que l'on peut encore récupérer les fichiers ...sont ils disponibles dans le code source de la page spécifique ou tu les avais noté auparavant ?Regarde la source de mon code en Python, tu auras ta réponse !
Tu veux surement parler d'injection SQL, il, ce n'est pas la méthode utilisé.Oui effectivement ... merci pour ta réponse ...
Ce type de programme sont souvent pourrit d'adware, rarement d'autre chose, mais je me méfie toujours.La définition d'écran de la VM est de 800x600, çà peut venir de la aussi ... pour ce qui est des adware, la page d'accueil de SoftwareInformer est ajoutée si on ne décoche pas l'option lors de l'installation. Mais il faut cliquez sur "Install Software Informer" pour qu'il s'installe ... FunWeb ds la RestaurationSystème n'a en fait rien à voir :NNN .. sorry, ce sont des résidus ...
Sinon, le crash du programme est souvent dû à l'instabilité des machines virtuelles, ont ne peut rien conclure à partir de ça.
C'est sympa .. merci @ toi ...Thanks pour l'outil ! Sympa les articles sur ton site, n'hésites pas à partager des info's surJ'y tâcherais !
le reverse engineering ou pour récuperer des données d'un malware ... D'avance merci ...