MS antivirus

Fermé
Helene - 6 oct. 2008 à 04:28
 Helene - 7 oct. 2008 à 08:24
Bonjour,
Quelqu'un pourrait-il me guider et me dire comment me débarrasser de MS antivirus??
Merci!
A voir également:

8 réponses

J'ai deja essaye mais le rogue remover ne detecte pas le virus... D'autre solution??
0
J'utilise internet explorer.

Les deux sites proposent spyhunter, qui scanne et detecte le virus, mais fait payer pour l'enlever.

Et pour l'enlever soi-meme, je ne sais pas tres bien comment m'y prendre - MS antivirus n'apparait pas dans les processus, et il y a beaucoup de fichier MSA sur mon ordinateur, mais j'ai peur qu'ils n'aient rien a voir avec le virus...

Merci de ton aide. Je suis ouverte a toute suggestion...?
0
Aussi, j'utilise panda antivus, qui n'y voit que du feu...
0
douchka66 Messages postés 1665 Date d'inscription samedi 31 mai 2008 Statut Membre Dernière intervention 12 mars 2015 46
6 oct. 2008 à 05:57
bonjour helene
scan complet avec malwarebytes post le rapport ensuite ccleaner ok
-1
Voila deja le log de malwarebyte:

Malwarebytes' Anti-Malware 1.28
Database version: 1234
Windows 5.1.2600 Service Pack 3

10/6/2008 6:19:36 PM
mbam-log-2008-10-06 (18-19-35).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 136061
Time elapsed: 1 hour(s), 2 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 8
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 27

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\fccCvWnm.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\gkrijngp.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\cbXqomLb.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{376efd74-7aa4-44a4-9e39-e374ed3139a9} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxqomlb (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{376efd74-7aa4-44a4-9e39-e374ed3139a9} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3ede4750-d439-48c2-a0e7-1f55a40a6412} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{3ede4750-d439-48c2-a0e7-1f55a40a6412} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\5d775487 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{376efd74-7aa4-44a4-9e39-e374ed3139a9} (Trojan.Vundo) -> Delete on reboot.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\fcccvwnm -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\fcccvwnm -> Delete on reboot.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\cbXqomLb.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\fccCvWnm.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\mnWvCccf.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mnWvCccf.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dbqalpsn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nsplaqbd.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gkrijngp.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pgnjirkg.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kpxmnfdr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rdfnmxpk.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ltywabar.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rabawytl.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP534\A0052414.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP534\A0052436.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP536\A0052521.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP536\A0052524.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP537\A0052594.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP537\A0052595.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP537\A0052657.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ5E.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ63.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ64.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ65.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ66.tmp (Adware.Adspy) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ67.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Me\Local Settings\Temporary Internet Files\Content.IE5\DMUR8HVW\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.

Je lance ccleaner.
Merci!
0
douchka66 Messages postés 1665 Date d'inscription samedi 31 mai 2008 Statut Membre Dernière intervention 12 mars 2015 46
6 oct. 2008 à 19:20
re tu as ton rapport tu supprimes dans quarantaine et ccleaner normalement tranquille a +
-1

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Je crois bien que le probleme est resolu... Super.
Merci beaucoup, beaucoup de ton aide!!!
0
lou421 Messages postés 55 Date d'inscription vendredi 26 septembre 2008 Statut Membre Dernière intervention 21 mars 2009
6 oct. 2008 à 04:52
Salut,
va voir la

http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/antivirus-antivirus-resolu-sujet_47092_1.htm

A+
-1
lou421 Messages postés 55 Date d'inscription vendredi 26 septembre 2008 Statut Membre Dernière intervention 21 mars 2009
6 oct. 2008 à 05:16
ok

quel antivirus utilises-tu ?

Navigateur IE, Mozilla autre...?
-1
lou421 Messages postés 55 Date d'inscription vendredi 26 septembre 2008 Statut Membre Dernière intervention 21 mars 2009
6 oct. 2008 à 05:25
va voir ici

https://www.411-spyware.com/fr/

plus d'info

https://fr.pcthreat.com/ (vérifier s'il est en free)

bon courage
-1