MS antivirus

Helene -  
 Helene -
Bonjour,
Quelqu'un pourrait-il me guider et me dire comment me débarrasser de MS antivirus??
Merci!
Configuration: Windows XP
Internet Explorer 7.0

8 réponses

  1. Helene
     
    J'ai deja essaye mais le rogue remover ne detecte pas le virus... D'autre solution??
    0
  2. Helene
     
    J'utilise internet explorer.

    Les deux sites proposent spyhunter, qui scanne et detecte le virus, mais fait payer pour l'enlever.

    Et pour l'enlever soi-meme, je ne sais pas tres bien comment m'y prendre - MS antivirus n'apparait pas dans les processus, et il y a beaucoup de fichier MSA sur mon ordinateur, mais j'ai peur qu'ils n'aient rien a voir avec le virus...

    Merci de ton aide. Je suis ouverte a toute suggestion...?
    0
  3. Helene
     
    Aussi, j'utilise panda antivus, qui n'y voit que du feu...
    0
    1. douchka66 Messages postés 1693 Date d'inscription   Statut Membre Dernière intervention   48
       
      bonjour helene
      scan complet avec malwarebytes post le rapport ensuite ccleaner ok
      -1
  4. Helene
     
    Voila deja le log de malwarebyte:

    Malwarebytes' Anti-Malware 1.28
    Database version: 1234
    Windows 5.1.2600 Service Pack 3

    10/6/2008 6:19:36 PM
    mbam-log-2008-10-06 (18-19-35).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 136061
    Time elapsed: 1 hour(s), 2 minute(s), 56 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 3
    Registry Keys Infected: 8
    Registry Values Infected: 2
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 27

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    C:\WINDOWS\system32\fccCvWnm.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\gkrijngp.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\cbXqomLb.dll (Trojan.Vundo) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{376efd74-7aa4-44a4-9e39-e374ed3139a9} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxqomlb (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{376efd74-7aa4-44a4-9e39-e374ed3139a9} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3ede4750-d439-48c2-a0e7-1f55a40a6412} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{3ede4750-d439-48c2-a0e7-1f55a40a6412} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\5d775487 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{376efd74-7aa4-44a4-9e39-e374ed3139a9} (Trojan.Vundo) -> Delete on reboot.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\fcccvwnm -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\fcccvwnm -> Delete on reboot.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\system32\cbXqomLb.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\fccCvWnm.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\mnWvCccf.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mnWvCccf.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dbqalpsn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\nsplaqbd.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gkrijngp.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\pgnjirkg.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\kpxmnfdr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\rdfnmxpk.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ltywabar.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\rabawytl.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP534\A0052414.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP534\A0052436.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP536\A0052521.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP536\A0052524.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP537\A0052594.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP537\A0052595.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{BF5182F3-21D6-43D5-968F-116F6DF977E7}\RP537\A0052657.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ5E.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ63.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ64.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ65.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ66.tmp (Adware.Adspy) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\APQ67.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Me\Local Settings\Temporary Internet Files\Content.IE5\DMUR8HVW\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.

    Je lance ccleaner.
    Merci!
    0
    1. douchka66 Messages postés 1693 Date d'inscription   Statut Membre Dernière intervention   48
       
      re tu as ton rapport tu supprimes dans quarantaine et ccleaner normalement tranquille a +
      -1
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Helene
     
    Je crois bien que le probleme est resolu... Super.
    Merci beaucoup, beaucoup de ton aide!!!
    0
  7. lou421 Messages postés 61 Statut Membre
     
    Salut,
    va voir la

    http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/antivirus-antivirus-resolu-sujet_47092_1.htm

    A+
    -1
  8. lou421 Messages postés 61 Statut Membre
     
    ok

    quel antivirus utilises-tu ?

    Navigateur IE, Mozilla autre...?
    -1