Problemes de trojan avec vista

samd Messages postés 7 Statut Membre -  
 Utilisateur anonyme -
Bonjour, je suis nouvelles sur ce site et pas très douée en informatique.
j'ai window vista et avast comme anti virus j'ai des cheveaux de trois dans mon ordinateur je ne peu pas les supprimers car il sont utilisés par windows??????ils sont dans C:WINDOWS SYSTEM 32
que dois je faire. mon ordi. rame vraiment. Merci d'avance pour votre aide.
Configuration: Windows Vista
Internet Explorer 7.0

3 réponses

  1. Utilisateur anonyme
     
    Salut alors désinstalle tous tes logiciel de sécurité. Et installe AntiVir,Malwarebytes Anti-Malware et Kerio.

    AntiVir: https://www.01net.com/outils/telecharger/windows/Securite/antivirus-antitrojan/fiches/tele13198.html
    Tutoriel AntiVir: https://www.malekal.com/avira-free-security-antivirus-gratuit/

    Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe
    Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm

    Kerio: https://www.01net.com/outils/telecharger/windows/Securite/firewall/fiches/tele22418.html
    Tutoriel Kerio: https://forums.cnetfrance.fr

    PS: TU LES INSTALLES SEULEMENT ET TU NE FAIS PAS D'ANALYSE. TU FAIS UNE MISE A JOUR A ANTIVIR ET MALWAREBYTES ANTI-MALWARE. VOILA FAIT VITE.
    0
    1. samd Messages postés 7 Statut Membre
       
      J'ai fait ce que tu ma noté mais j'ai du redemarer mon ordi et antivir c'est mis en route tout seul
      j'ai plein de fenetres qui s'ouvrent me disant qu'il y a un trojan tr/vundo.gen je ne sais pas faire de mise a jour ca bloque et je dois redemarer le pc.???? rien ne fonctionne ni refuser l'acces ni la quarantaine ni ignorer??
      0
      1. Utilisateur anonyme > samd Messages postés 7 Statut Membre
         
        Ok tu cliques sur "delete".

        Tu fais un scan en mode sans échec avec AntiVir. Tu lances le scan et si il détecte un virus (normalement oui) tu cliques sur "delete" et "apply sélection to all following détections. (pour qu'il le supprimes automatiquement). A la fin du scan tu cliques sur "report" tu redémarre en mode normal puis tu me postes le rapport.

        Mode sans Echec:

        Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
        Sélectionner "Mode sans échec" et appuie sur [Entrée]
        Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
        Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm

        Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.

        PS: JE TE CONSEILLE D'ENREGISTRER CE MESSAGE DANS TON BUREAU OU CAS OU.
        0
      2. samd Messages postés 7 Statut Membre > Utilisateur anonyme
         
        Voila j'espere que je l'ai fait correctement.

        Avira AntiVir Personal
        Report file date: vendredi 2 mai 2008 21:23

        Scanning for 1248213 virus strains and unwanted programs.

        Licensed to: Avira AntiVir PersonalEdition Classic
        Serial number: 0000149996-ADJIE-0001
        Platform: Windows Vista
        Windows version: (plain) [6.0.6000]
        Boot mode: Save mode
        Username: carol
        Computer name: PC-DE-CAROL

        Version information:
        BUILD.DAT : 8.1.00.295 16479 Bytes 9/04/2008 16:24:00
        AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
        AVSCAN.DLL : 8.1.1.0 53505 Bytes 7/02/2008 08:43:37
        LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
        LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
        ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
        ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 7/03/2008 13:08:58
        ANTIVIR2.VDF : 7.0.3.197 1260032 Bytes 22/04/2008 18:26:49
        ANTIVIR3.VDF : 7.0.3.243 276992 Bytes 2/05/2008 18:26:51
        Engineversion : 8.1.0.37
        AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
        AESCRIPT.DLL : 8.1.0.28 233851 Bytes 2/05/2008 18:27:00
        AESCN.DLL : 8.1.0.15 119157 Bytes 2/05/2008 18:26:59
        AERDL.DLL : 8.1.0.20 418165 Bytes 2/05/2008 18:26:59
        AEPACK.DLL : 8.1.1.4 364918 Bytes 2/05/2008 18:26:58
        AEOFFICE.DLL : 8.1.0.18 192890 Bytes 2/05/2008 18:26:57
        AEHEUR.DLL : 8.1.0.21 1196407 Bytes 2/05/2008 18:26:56
        AEHELP.DLL : 8.1.0.14 115063 Bytes 2/05/2008 18:26:53
        AEGEN.DLL : 8.1.0.18 299381 Bytes 2/05/2008 18:26:53
        AEEMU.DLL : 8.1.0.5 430450 Bytes 7/04/2008 15:34:43
        AECORE.DLL : 8.1.0.27 168310 Bytes 2/05/2008 18:26:52
        AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
        AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
        AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
        AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
        AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
        AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
        SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
        SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
        NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
        RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
        RCTEXT.DLL : 8.0.32.0 86273 Bytes 6/03/2008 12:02:11

        Configuration settings for the scan:
        Jobname..........................: Local Drives
        Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\alldrives.avp
        Logging..........................: low
        Primary action...................: interactive
        Secondary action.................: ignore
        Scan master boot sector..........: on
        Scan boot sector.................: on
        Boot sectors.....................: C:, E:, F:, G:, H:, D:,
        Scan memory......................: on
        Process scan.....................: on
        Scan registry....................: on
        Search for rootkits..............: off
        Scan all files...................: All files
        Scan archives....................: on
        Recursion depth..................: 20
        Smart extensions.................: on
        Macro heuristic..................: on
        File heuristic...................: medium

        Start of the scan: vendredi 2 mai 2008 21:23

        The scan of running processes will be started
        Scan process 'avscan.exe' - '1' Module(s) have been scanned
        Scan process 'avcenter.exe' - '1' Module(s) have been scanned
        Scan process 'HelpPane.exe' - '1' Module(s) have been scanned
        Scan process 'explorer.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'lsm.exe' - '1' Module(s) have been scanned
        Scan process 'lsass.exe' - '1' Module(s) have been scanned
        Scan process 'services.exe' - '1' Module(s) have been scanned
        Scan process 'winlogon.exe' - '1' Module(s) have been scanned
        Scan process 'wininit.exe' - '1' Module(s) have been scanned
        Scan process 'csrss.exe' - '1' Module(s) have been scanned
        Scan process 'csrss.exe' - '1' Module(s) have been scanned
        Scan process 'smss.exe' - '1' Module(s) have been scanned
        18 processes with 18 modules were scanned

        Starting master boot sector scan:
        Master boot sector HD0
        [INFO] No virus was found!
        Master boot sector HD1
        [INFO] No virus was found!
        [WARNING] Le périphérique n'est pas prêt.
        [INFO] Please restart the search with Administrator rights
        Master boot sector HD2
        [INFO] No virus was found!
        [WARNING] Le périphérique n'est pas prêt.
        [INFO] Please restart the search with Administrator rights
        Master boot sector HD3
        [INFO] No virus was found!
        [WARNING] Le périphérique n'est pas prêt.
        [INFO] Please restart the search with Administrator rights
        Master boot sector HD4
        [INFO] No virus was found!
        [WARNING] Le périphérique n'est pas prêt.
        [INFO] Please restart the search with Administrator rights

        Start scanning boot sectors:
        Boot sector 'C:\'
        [INFO] No virus was found!
        Boot sector 'E:\'
        [INFO] In the drive 'E:\' no data medium is inserted!
        Boot sector 'F:\'
        [INFO] In the drive 'F:\' no data medium is inserted!
        Boot sector 'G:\'
        [INFO] In the drive 'G:\' no data medium is inserted!
        Boot sector 'H:\'
        [INFO] In the drive 'H:\' no data medium is inserted!

        Starting to scan the registry.
        C:\Windows\System32\eqscddfy.dll
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!

        The registry was scanned ( '17' files ).


        Starting the file scan:

        Begin scan in 'C:\' <HDD>
        C:\pagefile.sys
        [WARNING] The file could not be opened!
        C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloaderxot.zip
        [DETECTION] Contains suspicious code GEN/PwdZIP
        [NOTE] The fund was classified as suspicious.
        [NOTE] The file was moved to '488a6c24.qua'!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\41H1MRDV\css4[1]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\41H1MRDV\css4[2]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\41H1MRDV\css4[3]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5NTSA2TH\css4[1]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5NTSA2TH\css4[2]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5NTSA2TH\css4[3]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L1CL98BL\css4[1]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L1CL98BL\css4[2]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L1CL98BL\css4[3]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P3KTBOQD\css4[1]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P3KTBOQD\kriv[1]
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Users\carol\Downloads\MediaTubeCodec_ver1.668.2.exe
        [DETECTION] Is the Trojan horse TR/Dldr.Zlob.luh
        [NOTE] The file was deleted!
        C:\Windows\qadovnel.dll
        [DETECTION] Is the Trojan horse TR/Vapsup.epj
        [NOTE] The file was deleted!
        C:\Windows\System32\ddCvSIxY.dll
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [WARNING] The file could not be deleted!
        C:\Windows\System32\khFWQjgG.dll
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Windows\System32\nazmxivy.exe
        [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
        [NOTE] The file was deleted!
        C:\Windows\System32\wvuRiJBt.dll
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        C:\Windows\System32\wvuTnOiF.dll
        [DETECTION] Is the Trojan horse TR/Vundo.Gen
        [NOTE] The file was deleted!
        Begin scan in 'E:\'
        Search path E:\ could not be opened!
        Le périphérique n'est pas prêt.

        Begin scan in 'F:\'
        Search path F:\ could not be opened!
        Le périphérique n'est pas prêt.

        Begin scan in 'G:\'
        Search path G:\ could not be opened!
        Le périphérique n'est pas prêt.

        Begin scan in 'H:\'
        Search path H:\ could not be opened!
        Le périphérique n'est pas prêt.

        Begin scan in 'D:\'
        Search path D:\ could not be opened!
        Le périphérique n'est pas prêt.



        End of the scan: vendredi 2 mai 2008 21:48
        Used time: 26:00 min

        The scan has been done completely.

        13066 Scanning directories
        256701 Files were scanned
        19 viruses and/or unwanted programs were found
        1 Files were classified as suspicious:
        18 files were deleted
        0 files were repaired
        1 files were moved to quarantine
        0 files were renamed
        1 Files cannot be scanned
        256682 Files not concerned
        3742 Archives were scanned
        6 Warnings
        19 Notes
        0
  2. samd Messages postés 7 Statut Membre
     
    PS: Kerio n'est pas compatible avec vista
    et j'ai de nouveau eu les fenetres comme tout a l'heure
    "attention detection
    c:/windows/system32/ddCvSIxY.dll
    is the trojan horse TR/Vundo.gen

    qui ce sont ouvert au demarage
    0
  3. samd Messages postés 7 Statut Membre
     
    PS: Kerio n'est pas compatible avec vista
    et j'ai de nouveau eu les fenetres comme tout a l'heure
    "attention detection
    c:/windows/system32/ddCvSIxY.dll
    is the trojan horse TR/Vundo.gen

    qui ce sont ouvert au demarage
    0
    1. Utilisateur anonyme
       
      Tu as un virus en quarantaine de AntiVir supprime le.
      0
    2. Utilisateur anonyme > Utilisateur anonyme
       
      Et si il détecte un virus cliques sur "delete".
      0
    3. samd Messages postés 7 Statut Membre > Utilisateur anonyme
       
      J'ai tout supprimé dans la quarantaine mais les ecrans reviennent quand meme
      j'ai essayer move to quarantaine
      delete
      deny acces
      rien ne fonctionne il revient
      0
    4. Utilisateur anonyme > samd Messages postés 7 Statut Membre
       
      Non tu fais que "delete". Maintenant fais un scan en ligne avec BitDefender.

      BitDefender: http://www.bitdefender.fr/scan_fr/scan8/ie.html
      tutoriel BitDefender en ligne: http://cybersecurite.xooit.com/t201-Scan-en-ligne-BitDefender.htm

      0
    5. samd Messages postés 7 Statut Membre > Utilisateur anonyme
       
      bonjour,
      j'ai enfin pu me reconnecter mais j'ai toujours le même problème
      bitdefender a bloque il n'arrive pas a analyser.
      je dois passer par firefox ou je ne sais pas avoir acces a internet et de que j'allume,
      antivir se met en route et j'ai plein de fenêtres qui s'ouvrent
      exemple, virus trouvé....
      trojan horse tr/truvo.gen
      0