
j'ai a nouveau un probleme avec internet,des fenetres de pub s'ouvre toute seul
j'ai déja eu un cas similaire, voir ce topic:
topic13409.html
si on pouvais refaire ensemble la manip pour ce cas...
merci d'avance
Code : Tout sélectionner
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Version de la base de données: 5721
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18999
09/02/2011 17:20:04
mbam-log-2011-02-09 (17-20-04).txt
Type d'examen: Examen rapide
Elément(s) analysé(s): 140221
Temps écoulé: 8 minute(s), 3 seconde(s)
Processus mémoire infecté(s): 3
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 6
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 12
Processus mémoire infecté(s):
c:\Users\nawak\AppData\Local\Temp\Rs0.exe (Trojan.Agent) -> 4332 -> Unloaded process successfully.
c:\Users\nawak\AppData\Local\Temp\Rsy.exe (Trojan.Agent) -> 5300 -> Unloaded process successfully.
c:\Users\nawak\AppData\Local\Temp\Rsx.exe (Trojan.Agent) -> 4016 -> Unloaded process successfully.
Module(s) mémoire infecté(s):
c:\Users\nawak\AppData\Local\Temp\sshnas21.dll (Trojan.Agent) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\CE8SIIFGSU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\DD1APJEZAI (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Metropolis (Trojan.Agent) -> Value: Metropolis -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NtWqIVLZEWZU (Trojan.Agent) -> Value: NtWqIVLZEWZU -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\CE8SIIFGSU (Trojan.Agent) -> Value: CE8SIIFGSU -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\Users\nawak\AppData\Local\Temp\sshnas21.dll (Trojan.Agent) -> Delete on reboot.
c:\Users\nawak\AppData\Local\Temp\Rs0.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\nawak\AppData\Local\Temp\Rsy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\nawak\AppData\Local\Temp\Rsx.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\nawak\AppData\Local\Temp\Rs1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\nawak\AppData\Local\Temp\Rs2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\nawak\AppData\Local\Temp\Rsv.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\nawak\AppData\Local\Temp\Rsw.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\nawak\AppData\Local\Temp\Rsz.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{62c40aa6-4406-467a-a5a5-dfdf1b559b7a}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.