Aujourd'hui, j'ai eu un ordinateur qui a affiché un message de la part
d'Avast, comme quoi il y avait un Trojan Spark. Avast l'a supprimé, et
ensuite le PC ne redémarrait plus, il a fallu réinstaller Windows XP. Le
rapport Avast me laisse comprendre pourquoi :
22/08/2005 15:01:35 SYSTEM 1420 Sign of "Win32:Spark
[Trj]" has been found in "C:\WINDOWS\SYSTEM32\GDI32.DLL" file.
22/08/2005 15:03:57 SYSTEM 1420 Sign of "Win32:Spark
[Trj]" has been found in "C:\windows\SERVIC~1\i386\gdi32.dll" file.
22/08/2005 15:26:06 Vaillant 1972 Sign of "Win32:Spark
[Trj]" has been found in "c:\program files\imagine
editions\hellodoc\hellodoc.exe" file.
22/08/2005 15:26:16 Vaillant 1972 Sign of "Win32:Spark
[Trj]" has been found in "c:\program
files\logitech\setpoint\macros\macrocore.dll" file.
22/08/2005 15:28:18 Vaillant 1972 Sign of "Win32:Spark
[Trj]" has been found in "c:\program files\sagem\sagem f@st
800-840\dslmon.exe" file.
22/08/2005 15:28:31 Vaillant 1972 Sign of "Win32:Spark
[Trj]" has been found in "c:\windows\system32\dssenh.dll" file.
22/08/2005 15:28:41 Vaillant 1972 Sign of "Win32:Spark
[Trj]" has been found in "c:\windows\system32\mvsmpl32.dll" file.
22/08/2005 15:28:44 SYSTEM 1420 Sign of "Win32:Spark
[Trj]" has been found in "C:\windows\SERVIC~1\i386\dssenh.dll" file.
22/08/2005 15:29:22 Vaillant 1972 Sign of "Win32:Spark
[Trj]" has been found in "c:\windows\system32\wbem\esscli.dll" file.
22/08/2005 15:29:33 Vaillant 1972 Sign of "Win32:Spark
[Trj]" has been found in "c:\windows\system\cmicnfg.cpl" file.
22/08/2005 15:29:37 SYSTEM 1420 Sign of "Win32:Spark
[Trj]" has been found in "C:\windows\SERVIC~1\i386\esscli.dll" file.
22/08/2005 15:29:54 Vaillant 1972 Sign of "Win32:Spark
[Trj]" has been found in "c:\windows\system32\nerocheck.exe" file.
22/08/2005 15:30:02 Vaillant 1972 Sign of "Win32:Spark
[Trj]" has been found in "c:\windows\system32\fontext.dll" file.
22/08/2005 15:30:14 SYSTEM 1420 Sign of "Win32:Spark
[Trj]" has been found in "C:\windows\SERVIC~1\i386\fontext.dll" file.
22/08/2005 15:33:02 SYSTEM 1420 Sign of "Win32:Spark
[Trj]" has been found in "C:\WINDOWS\HELP\SBSI\TRAINING\ORUN32.EXE" file.
C'est sûr qu'en ayant enlevé gdi32.dll, Windows avait du mal à démarrer.
Questions :
- Est-ce plausible que spark ait infecté tous ces fichiers ?
- Est-ce normal qu'Avast ait effacé ces fichiers, bloquant l'ordinateur, et
nécessitant la réinstallation des logiciels ?
- Que me conseillez-vous pour que ça ne se reproduise pas ? (Déjà, j'ai
installé Ms Antispyware, qui n'était pas encore présent sur cet ordi)