Malwarebytes' Anti-Malware 1.50.1.1100
http://www.malwarebytes.orgVersion de la base de données: 6172
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19019
26/03/2011 01:03:49
mbam-log-2011-03-26 (01-03-49).txt
Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 409997
Temps écoulé: 1 heure(s), 40 minute(s), 51 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 16
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
c:\Users\jepa\AppData\Local\nscher.dll (Trojan.Hiloti) -> Delete on reboot.
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Fzuqiwareheguri (Trojan.Hiloti) -> Value: Fzuqiwareheguri -> Delete on reboot.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\Users\jepa\AppData\Local\nscher.dll (Trojan.Hiloti) -> Delete on reboot.
c:\Users\jepa\AppData\Local\temp\setup1907431744.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\setup213506256.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\setup2739116864.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\setup3954817616.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\setup4103216976.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\setup4205995840.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\setup468761424.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\21A5.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\21B6.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\2983.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\4B3.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\arexnwmsco.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\CD.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\setup567277136.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\jepa\AppData\Local\temp\wornsacmex.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.