22 malware/virus detectes malwaremagabytes

Résolu/Fermé
zdan - 29 déc. 2010 à 20:57
Redbart Messages postés 21068 Date d'inscription dimanche 16 décembre 2007 Statut Membre Dernière intervention 12 avril 2024 - 29 déc. 2010 à 21:09
Bonjour à tous,



Windows XP / Internet Explorer 7.0

J'ai des fenetres internet intempestives, jusqu'a 15, qui s'ouvrent sans raison
J'ai traité les fichiers, maintenant comment etre certain de m'en etre débarrassé ??

Merci d'avance pour votre aide.

Voici le rapport :

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5417

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

29/12/2010 20:37:23
mbam-log-2010-12-29 (20-37-23).txt

Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 289424
Temps écoulé: 1 heure(s), 18 minute(s), 1 seconde(s)

Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 8
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 25

Processus mémoire infecté(s):
c:\WINDOWS\Znocya.exe (Trojan.FraudPack) -> 9752 -> Unloaded process successfully.

Module(s) mémoire infecté(s):
c:\WINDOWS\system32\sshnas21.dll (Rootkit.Agent) -> Delete on reboot.

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Victor Chandler (PUP.Casino) -> Not selected for removal.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\JP595IR86O (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\JP595IR86O (Trojan.FraudPack) -> Value: JP595IR86O -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\WINDOWS\system32\sshnas21.dll (Rootkit.Agent) -> Delete on reboot.
c:\Documents and Settings\papa\Local Settings\Temp\Zmm.exe (Trojan.FraudPack) -> Delete on reboot.
c:\Documents and Settings\papa\Local Settings\Temp\Zml.exe (Trojan.FraudPack) -> Delete on reboot.
c:\WINDOWS\Znocya.exe (Trojan.FraudPack) -> Delete on reboot.
c:\documents and settings\papa\local settings\Temp\sshnas21.dll (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmj.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmk.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmn.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmo.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmp.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmq.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmr.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zms.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmt.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmu.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmv.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmw.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmx.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\Temp\Zmy.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\Poker\victor chandler\_setupcasino_12e5[1].exe (PUP.Casino) -> Not selected for removal.
c:\documents and settings\papa\local settings\application data\dsbqhnc_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
c:\documents and settings\papa\local settings\application data\dsbqhnc_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{62c40aa6-4406-467a-a5a5-dfdf1b559b7a}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
A voir également:

1 réponse

Redbart Messages postés 21068 Date d'inscription dimanche 16 décembre 2007 Statut Membre Dernière intervention 12 avril 2024 3 219
Modifié par Redbart le 29/12/2010 à 21:10
Bsr
certains malwares ne seront supprimés qu'au redémarrage

dès que tu auras le temps fait un scan complet du pc avec MBAM
après update

puis de même avec ton anti virus

as tu un anti spyware? windows defender suffit, vérifie qu'il est actif
0