Total security

lisandro1991 -  
Xplode Messages postés 9212 Statut Contributeur sécurité -
salut a tous,j'ai moi aussi un petit probleme avec ce fameux total security
J'ai le cadenas qui apparait en bas a doite de mon ecran et qui me dit toutes les 5 minutes que je suis infecté
Quelqu'un pourrait m'aider a l'enlever ? je vous remercie d'avance !!
A voir également:

29 réponses

lisandro1991
 
le scan d'ad remover ne fonctionne pas,comment je fais pr lancer combofix ?
0
mickael zenn38
 
Bonjour, Comme beaucoup de personne j'ai aussi un problème avec Total security
0
Xplode Messages postés 9212 Statut Contributeur sécurité 726
 
@ Lisandro --->

Malwarebyte's anti-malware ----->

[x] Télécharge Malwarebyte's anti-malware (MBAM) à cette adresse : http://www.malwarebytes.org/mbam/program/mbam-setup.exe

[x] Installe le

[x] Un tutoriel pour son utilisation est disponible ici : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

[x] Suis les indications données sur le lien précédent puis copie/colle le rapport généré dans ton prochain message

@ mickael

Crée un nouveau sujet pour qu'on s'occupe de toi
0
lisandro1991
 
Malwarebytes' Anti-Malware 1.40
Version de la base de données: 2705
Windows 5.1.2600 Service Pack 3

28/08/2009 23:14:52
mbam-log-2009-08-28 (23-14-51).txt

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 174409
Temps écoulé: 2 hour(s), 1 minute(s), 25 second(s)

Processus mémoire infecté(s): 5
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 3
Valeur(s) du Registre infectée(s): 13
Elément(s) de données du Registre infecté(s): 6
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 53

Processus mémoire infecté(s):
C:\documents and settings\lannier\local settings\application data\ykwbtfqb.exe (Adware.Navipromo.H) -> Unloaded process successfully.
C:\Documents and Settings\All Users\Application Data\17325934\17325934.exe (Rogue.Multiple.H) -> Unloaded process successfully.
C:\WINDOWS\system32\mset.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\Documents and Settings\lannier\mset.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\system32\braviax.exe (Trojan.FakeAlert) -> Unloaded process successfully.

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DbgMgr (Malware.Trace) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MessengerSkinner.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ykwbtfqb (Adware.Navipromo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\17325934 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mset (Trojan.Downloader) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mset (Trojan.Downloader) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet connection wizard setup tool (Trojan.Downloader) -> Delete on reboot.
HKEY_CURRENT_USER\Control Panel\don't load\scui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\don't load\wscui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\braviax (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\braviax (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PC Antispyware 2010 (Rogue.PC_Antispyware2010) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RList (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32 (Trojan.Agent) -> Delete on reboot.

Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
C:\Documents and Settings\All Users\Application Data\17325934 (Rogue.Multiple.H) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\Documents and Settings\lannier\Local Settings\Application Data\ykwbtfqb_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Application Data\ykwbtfqb_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Application Data\ykwbtfqb.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Application Data\ykwbtfqb.exe (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\17325934\17325934.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\17325934\17325934 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\17325934\pc17325934ins (Rogue.Multiple.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wisdstr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_scui.cpl (Rogue.HomeAntiVirus) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\beep.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dllcache\figaro.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dllcache\beep.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN1.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN3.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN4.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\msupd_2.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN2.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN5.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN6.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN38.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN41.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN48.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN7.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BN9.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Local Settings\Temp\BNA.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP836\A0195485.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP836\A0195486.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP836\A0195497.cpl (Rogue.HomeAntiVirus) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP836\A0195501.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP836\A0195521.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP836\A0195525.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP835\A0193420.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP835\A0193421.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP835\A0193427.cpl (Rogue.HomeAntiVirus) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP835\A0193432.sys (Trojan.KillAV) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mset.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\mset.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\All Users\Application Data\Microsoft\Shortcuts\icwsetup.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Application Data\wiaserva.log (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\Internet Explorer\Connection Wizard\icwsetup.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aiujojbqz_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aiujojbqz_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\braviax.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cru629.dat (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nvs2.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\wpv371251285056.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Cookies\evyd.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Cookies\uvimemiqo.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\delself.bat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\oashdihasidhasuidhiasdhiashdiuasdhasd (Trace.Pandex) -> Quarantined and deleted successfully.
C:\WINDOWS\braviax.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\cru629.dat (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lannier\Menu Démarrer\Programmes\Démarrage\ikowin32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Xplode Messages postés 9212 Statut Contributeur sécurité 726
 
Parfait !

Plus de problèmes ?
0
lisandro1991
 
c'est bon ya plus de problemes ?
0
Xplode Messages postés 9212 Statut Contributeur sécurité 726
 
Ben je te demande justement si tu n'as plus de problèmes avec ton PC ?

Malwarebyte's à fait son boulot et il a viré l'infection total security.
0
lisandro1991
 
ah oui excuse !
non ça a l'air d'être bon,j'ai plus les icones des faux anti-virus qui s'affichent...
merci mille fois et bravo !
0
Xplode Messages postés 9212 Statut Contributeur sécurité 726
 
De rien, @+
0