Aide pour virus
Fermé
jefaax
Messages postés
2
Date d'inscription
jeudi 10 septembre 2009
Statut
Membre
Dernière intervention
10 septembre 2009
-
10 sept. 2009 à 15:13
jefaax Messages postés 2 Date d'inscription jeudi 10 septembre 2009 Statut Membre Dernière intervention 10 septembre 2009 - 10 sept. 2009 à 15:38
jefaax Messages postés 2 Date d'inscription jeudi 10 septembre 2009 Statut Membre Dernière intervention 10 septembre 2009 - 10 sept. 2009 à 15:38
A voir également:
- Aide pour virus
- Youtu.be virus - Accueil - Guide virus
- Svchost.exe virus - Guide
- Faux message virus ordinateur - Accueil - Arnaque
- Softonic virus ✓ - Forum Virus
- Faux message virus iphone - Forum iPhone
1 réponse
jefaax
Messages postés
2
Date d'inscription
jeudi 10 septembre 2009
Statut
Membre
Dernière intervention
10 septembre 2009
10 sept. 2009 à 15:38
10 sept. 2009 à 15:38
Je viens de faire l'analyse avec MBAM, il y avait plusieurs infections, voici le rapport :
Malwarebytes' Anti-Malware 1.40
Version de la base de données: 2771
Windows 5.1.2600 Service Pack 3
10/09/2009 15:37:11
mbam-log-2009-09-10 (15-37-11).txt
Type de recherche: Examen rapide
Eléments examinés: 90482
Temps écoulé: 8 minute(s), 41 second(s)
Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 3
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 4
Fichier(s) infecté(s): 6
Processus mémoire infecté(s):
C:\documents and settings\marie-lou\local settings\application data\ukbandd.exe (Adware.Navipromo.H) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo (Rogue.Eorezo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ukbandd (Adware.Navipromo.H) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\DoubleD\GamingHarbor Toolbar (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\DoubleD\GamingHarbor Toolbar\4.2.3.22530 (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\DoubleD\GamingHarbor Toolbar\4.2.3.22530\bin (Adware.DoubleD) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\ukbandd_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\ukbandd_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\ukbandd.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\ukbandd.exe (Adware.Navipromo.H) -> Delete on reboot.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\DoubleD\GamingHarbor Toolbar\4.2.3.22530\bin\stbup.exe (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Delete on reboot.
Malwarebytes' Anti-Malware 1.40
Version de la base de données: 2771
Windows 5.1.2600 Service Pack 3
10/09/2009 15:37:11
mbam-log-2009-09-10 (15-37-11).txt
Type de recherche: Examen rapide
Eléments examinés: 90482
Temps écoulé: 8 minute(s), 41 second(s)
Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 3
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 4
Fichier(s) infecté(s): 6
Processus mémoire infecté(s):
C:\documents and settings\marie-lou\local settings\application data\ukbandd.exe (Adware.Navipromo.H) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo (Rogue.Eorezo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ukbandd (Adware.Navipromo.H) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\DoubleD\GamingHarbor Toolbar (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\DoubleD\GamingHarbor Toolbar\4.2.3.22530 (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\DoubleD\GamingHarbor Toolbar\4.2.3.22530\bin (Adware.DoubleD) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\ukbandd_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\ukbandd_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\ukbandd.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\ukbandd.exe (Adware.Navipromo.H) -> Delete on reboot.
C:\Documents and Settings\Marie-Lou\Local Settings\Application Data\DoubleD\GamingHarbor Toolbar\4.2.3.22530\bin\stbup.exe (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Delete on reboot.