Faux antivirus(antivirus system 2011)

Fermé
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011 - 3 janv. 2011 à 12:40
 kams13n - 19 janv. 2011 à 17:47
Bonjour,



<depuis c matin j'ai un faux antivirus(antivirus system2011) qui est aparu impossible de m'en détacher impossible de télécharger koi ke se soit pour m'en débarrasser je suis bien embeter car en plus de ca novice ds ce domaine.le pc portable ke l'on ma preter hier n'est pas tt récent mais fonctionner bien jusque la.
Merci d'avance du coup de main et de la patiente que vous aurez si je doit vs donnez plus d'information.j'oubliais j'avai pourtant installer AVIRA...mais surement pas de la bonne facon.
A voir également:

129 réponses

Utilisateur anonyme
3 janv. 2011 à 18:58
evidemment....dans les temp...j'aurais pu y penser...!!!

lance Malwarebytes comme juju t a dit
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 19:07
dans les temp?j'ai pas compris?je l'ai lancer apres s'il demande de redemarrer toujours sans échec(je ne sais pas si j'ai installer Malwarebytes comme juju m'as di j'ai fai au mieux c pas facil)apres je post le raport c ca?
0
Utilisateur anonyme
3 janv. 2011 à 19:12
oui deja....apres je pense que ton pc ira deja mieux mais il restera encore surement des trucs à virer

on te suis , t'inquietes pas

n'oublie pas de tout supprimer à la fin du scan de MBAM
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 19:17
c'est cool les gars sans vous..... j'espere que se ne sera pas trop long que je puissse vous tenir au courant
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
3 janv. 2011 à 19:18
personne n'est pressé ici :)
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 19:24
ok :)
0
Utilisateur anonyme
3 janv. 2011 à 19:25
:)
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 19:36
il me demande de redemmarer oui mais sans échec?
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 19:48
j'ai redemarrer
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 19:55
j'arrive pas a poster le raport
0
Utilisateur anonyme
3 janv. 2011 à 20:04
heberge-le sur cijoint.fr puis donne le lien obtenu
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 20:16
desolé gen mais je ne sais pas le faire qu'est qur tu applelle héberge le sur cijoint et comment je fai
0
Utilisateur anonyme
3 janv. 2011 à 20:22
clique sur ce lien : http://www.cijoint.fr/

▶ Clique sur Parcourir et cherche le fichier ci-dessus.

▶ Clique sur Ouvrir.

▶ Clique sur "Cliquez ici pour déposer le fichier".

juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

▶ Copie ce lien dans ta réponse.
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 20:45
je suis entrain de m'énerver désoler je n'arrive le chemin por trouver le bloc note ya apication data je suis perdu
0
Utilisateur anonyme
3 janv. 2011 à 20:47
ok

ouvre malwarebytes , onglets rapports logs , puis choisis le dernier en date

une fois celui-ci ouvert , selectionne tout et copie-le dans un document texte que tu auras fait sur ton bureau

ensuite fournis ce documents texte
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
Modifié par crapoulou le 3/01/2011 à 21:09
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.


Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\BureMalwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bMalwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
d4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
au\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\BureMalwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bMalwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
d4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
au\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restorMalwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\BureMalwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bMalwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quar
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 20:51
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5448

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

03/01/2011 12:33:46
mbam-log-2011-01-03 (12-33-46).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 201577
Temps écoulé: 34 minute(s), 12 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 22

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\jErOmE\application data\802\bbzzkzz17.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\802\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\Bureau\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0394341.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395334.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395335.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395336.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP372\A0395516.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396530.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396547.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396548.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0396549.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399005.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{39bd4300-4480-448b-b553-0894580b6414}\RP373\A0399006.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\local settings\Temp\dffuck.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jErOmE\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
0
juju666 Messages postés 35446 Date d'inscription jeudi 18 décembre 2008 Statut Contributeur sécurité Dernière intervention 21 avril 2024 4 796
3 janv. 2011 à 21:01
Je suis de retour :)

Merci énormément à Gen Hackman

Pourquoi nous a tu collé 394 fois le rapport? ^^

Bien maintenant, redémarre en mode normal, et refais un scan complet avec malwarebytes'

@+

0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 21:20
http://www.cijoint.fr/cjlink.php?file=cj201101/cij31tRSjp.txt
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 21:21
c ca gen?
0
tonyno Messages postés 96 Date d'inscription mercredi 11 avril 2007 Statut Membre Dernière intervention 18 janvier 2011
3 janv. 2011 à 21:23
:) désoler je ne le voyai pas aparaitre et comme tu dit un grand merci a gen hackman et toi je refai un scan et je te di quand j'ai fini
0
Utilisateur anonyme
3 janv. 2011 à 22:14
▶ Télécharge ici : USBFIX sur ton bureau

branche tous tes periphériques sans les ouvrir

/!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."


sur l'icône Usbfix située sur ton Bureau.
Sur la page, clique sur le bouton :

▶ choisi l option Suppression

▶ UsbFix scannera ton pc , laisse travailler l outil.

▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

0