Afficher un message
Vieux 09/09/2005, 16h21   #5 (permalink)
Profil
Invité
Non Inscrit / Non Connecté
Ancienneté  100%
Ancienneté 100%
 
Messages: n/a
Téléchargements:
Uploads:
Par défaut

Backdoor.Prorat:

* Is a Backdoor Trojan horse that gives an attacker full control over your computer.
* Opens a port on the system.
* Is written in Delphi.
* Is packed with UPX.


Ce n'est donc pas un virus mais un troyen, il s'attaque aussi au registre.

Code:
# Disable System Restore (Windows Me/XP).
# Update the virus definitions.
# Restart the computer in Safe mode (Windows 95/98/Me) or Safe mode with Command Prompt (Windows 2000/XP).
# Reverse the changes made to the registry.
# Restart the computer in Safe mode or VGA mode (Windows Me/XP).
# Run a full system scan and delete all the files detected as Backdoor.Prorat.

en français:

#Désactiver la restauration du sytème Windows XP
#Mettre à jour la définition des virus Norton
#Redemarrer en mode sans echec
#annuler les changements fait au registre

Code:
# Type the following:

regedit

# Do one of the following:

    * Windows 2000/XP: Press Enter.
    * Windows 95/98/Me: Click OK.

# Navigate to each of these keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Policies\Explorer\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5Y99AE78-58TT-11dW-BE53-Y67078979Y}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

# For each one, in the right pane, if any of the following values are found, delete that value:

"MSNMESENGER"="%System%\Main.exe"

"DirectX for Microsoft Windows"="%System%\Fservice.exe"

"DirectX for Microsoft Windows"="%System%\Sservice.exe"

"StubPath"="C:\Windows\system\Sservice.exe"

# Do one of the following:

    * Windows 95/98/Me. Skip to step i.
    * Windows NT/2000/XP: Proceed with step g.

# Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

# In the right pane, modify the value:

"Shell"="explorer.exe %System%\Fservice.exe"

to:

"Shell"="explorer.exe"

# Exit the Registry Editor.
# Do one of the following:

          o Windows 95/98/Me: Skip to section 6.
          o Windows NT/2000/XP: Continue on to section 5.

#Relance norton et refais un scan



C'est un peu beaucoup pour un troyen, si ça te parait trop laborieux essayes des logiciels tels que troyan hunter etc.

Avis perso: Achete un routeur firewall(firewall physique donc) ya que ça de vrai, ça se configue une fois pour toute et tu bouffe plus de conneries comme ça
  Réponse avec citation