Bonjour a tous (et desole pour les accents, j'ecris de l'etranger),
Mon PC a ete infecte par un "ransomware" du type "Copyright Violation Alert" (comme ceci:
http://www.pc-infopratique.com/actualit ... adopi.html).
Je surfais via une session aux droits limites, donc le message intempestif bloque cette session, mais pas ma session admin.
J'ai fait un scan complet de mon ordi avec mon Antivirus (Symantec), Spybot et, ainsi que suggere sur le forum, Malwarebytes. Les programmes ont enleve des menaces (Trojan, spyware...), mais le message "Copyright Violation Alert" demeure, et bloque toujours ma session.
Voici donc le log du dernier scan complet effectue avec Malwarebytes:
--
Malwarebytes' Anti-Malware 1.45
http://www.malwarebytes.orgDatabase version: 4036
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
4/26/2010 11:37:28 AM
mbam-log-2010-04-26 (11-37-28).txt
Scan type: Full scan (C:\|)
Objects scanned: 226297
Time elapsed: 1 hour(s), 28 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\gautier.SIL081021\Application Data\0A8A44F98AA8A2CA9BD75A800FCE67D9\newupdate1142C.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\gautier.SIL081021\Application Data\APManager\uninstall.exe (Trojan.FraudTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\gautier.SIL081021\My Documents\perso\Adobe\Illustrator CS\Plug-ins\Photoshop Filters\Unsharpen Mask.8bf (Trojan.Spambot) -> Quarantined and deleted successfully.
--
Auriez-vous une suggestion pour virer ce ransomware?
Merci par avance!