L'ordinateur de ma grand mère a été infecté par un logiciel, ransomware ? Et je n'ai pas la démarche afin de supprimer les éventuel virus.
Le PC a été pris a distance par une personne malveillante.
Cette personne lui a demandé ces identifiants de compte bancaire par téléphone et a pu avoir accès apparemment a son ordinateur.
Dans le répertoire de téléchargement je vois un exécutable : connect_686784.exe
Et dans le répertoire AppData, j'ai des dossiers rang_fb_inst_6828.exe avec un exécutable ssrangsv.exe ainsi des fichiers logs à l’intérieur où le contenu ne m'inspire pas du tout confiance :
Code : Tout sélectionner
Mon Mar 01 18:40:53 2021
SSRCSVC: ERROR (Native(10872): File version: 0.5.35.0)
SSRCSVC: ERROR (Native(10872): Local time = [3-1-2021 - 18.40.53])
SSRCSVC: ERROR (Native(10872): UTC time = [3-1-2021 - 17.40.53])
SSRCSVC: INFO (Native(10872): Ctx params:: Index = -1, Str = )
Firewall: INFO (Native(10872): FW-> Add self.)
Firewall: INFO (Native(10816): FW-> App -> thread, Add = 1, Dir path = C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\.)
Firewall: INFO (Native(10816): FW-> Now checking file: [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangsv.exe])
Firewall: INFO (Native(9848): Initing COM: ApartmentThreaded_Ole1DDE, result (hr) = 0)
Firewall: INFO (Native(9848): FW-> Is it On? [1])
Firewall: INFO (Native(9848): FW-> Now checking file: [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangsv.exe])
Firewall: INFO (Native(9848): FW-> App file [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangsv.exe], is it already on = 1)
Firewall: INFO (Native(10816): FW-> Now checking file: [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangui.exe])
Firewall: INFO (Native(4076): Initing COM: ApartmentThreaded_Ole1DDE, result (hr) = 0)
Firewall: INFO (Native(4076): FW-> Is it On? [1])
Firewall: INFO (Native(4076): FW-> Now checking file: [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangui.exe])
Firewall: INFO (Native(4076): FW-> App file [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangui.exe], is it already on = 0)
Firewall: ERROR (Native(4076): FW->Failed to add the app to firewall... Error = -2147024894)
SSRCSVC: INFO (Native(10872): get ini ctx:: flow.)
SSRCSVC-ini: INFO (Native(10872): Initing COM: Ex(Default), result (hr) = 0)
SSRCSVC-ini: INFO (Native(10872): getInitValid:: process flow - URL = https://global.nexus.support.com/rang/win/connect?id=686784&os=windows, file = C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\rang_bstrap_msg_01.txt)
SSRCSVC-ini: INFO (Native(10872): do-Web-Work: scheme = curl, )
SSRCSVC-ini: ERROR (Native(5816): Reply to getInitValid::, HTTP Error. ;; Http status = 0, Response = curl_easy_perform() failed: Http status = 0, curl Code = 6, desc = Couldn't resolve host name ::
:: )
SSRCSVC-ini: INFO (Native(5816): Reply to getInitValid::, all done.. Result = -21)
SSRCSVC-ini: INFO (Native(5816): Reply to InitResponse, all done.. now signalling. Result = -21)
SSRCSVC-ini: ERROR (Native(10872): do-Web-Work - FAILED. scheme = curl, )
SSRCSVC-ini: INFO (Native(10872): do-Web-Work: scheme = json-rpc, )
SSRCSVC-ini: ERROR (Native(1216): Reply to getInitValid::, HTTP Error. ;; Http status = 12007, Response = :: )
SSRCSVC-ini: INFO (Native(1216): Reply to getInitValid::, all done.. Result = -21)
SSRCSVC-ini: INFO (Native(1216): Reply to InitResponse, all done.. now signalling. Result = -21)
SSRCSVC-ini: ERROR (Native(10872): do-Web-Work - FAILED. scheme = json-rpc, )
SSRCSVC-ini: INFO (Native(10872): do-Web-Work - complete. result = -21,)
SSRCSVC-ini: INFO (Native(10872): getInitValid:: process flow - complete. result = -21,)
Firewall: INFO (Native(10872): FW-> Add self.)
Firewall: INFO (Native(4668): FW-> App -> thread, Add = 0, Dir path = C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\.)
Firewall: INFO (Native(4668): FW-> Now checking file: [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangsv.exe])
Firewall: INFO (Native(8700): Initing COM: ApartmentThreaded_Ole1DDE, result (hr) = 0)
Firewall: INFO (Native(8700): FW-> Is it On? [1])
Firewall: INFO (Native(8700): FW-> Now checking file: [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangsv.exe])
Firewall: INFO (Native(8700): FW-> App file [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangsv.exe], is it already on = 1)
Firewall: INFO (Native(8700): FW-> App file [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangsv.exe], removed from firewall.)
Firewall: INFO (Native(4668): FW-> Now checking file: [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangui.exe])
Firewall: INFO (Native(2804): Initing COM: ApartmentThreaded_Ole1DDE, result (hr) = 0)
Firewall: INFO (Native(2804): FW-> Is it On? [1])
Firewall: INFO (Native(2804): FW-> Now checking file: [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangui.exe])
Firewall: INFO (Native(2804): FW-> App file [C:\Users\Nicole\AppData\Local\Temp\rang_fb_inst_6828\ssrangui.exe], is it already on = 0)
FRST : https://pjjoint.malekal.com/files.php?i ... 2o7f10w6b8
Addition : https://pjjoint.malekal.com/files.php?i ... 11m14o15d9
Shortcut : https://pjjoint.malekal.com/files.php?i ... j6e8c11y12
Merci d'avance pour l'aide que vous pourrez m'apporter