CONNEXION
  • RetourJeux
    • Sorties
    • Hit Parade
    • Les + populaires
    • Les + attendus
    • Soluces
    • Tous les Jeux
    • Gaming
  • RetourActu Gaming
    • News
    • Astuces
    • Tests
    • Previews
    • Toute l'actu gaming
  • RetourBons plans
    • Bons plans
    • Bons plans Smartphone
    • Bons plans Hardware
    • Bons plans Image et Son
    • Bons plans Amazon
    • Bons plans Cdiscount
    • Bons plans Decathlon
    • Bons plans Fnac
    • Tous les Bons plans
  • RetourJVTech
    • Actus High-Tech
    • Intelligence Artificielle
    • Smartphones
    • Mobilité urbaine
    • Hardware
    • Image et son
    • Tutoriels
    • Tests produits High-Tech
    • Guides d'achat High-Tech
    • JVTech
  • RetourCulture
    • Actus Culture
    • Culture
  • RetourVidéos
    • A la une
    • Gaming Live
    • Vidéos Tests
    • Vidéos Previews
    • Gameplay
    • Trailers
    • Chroniques
    • Replay Web TV
    • Toutes les vidéos
  • RetourForums
    • Hardware PC
    • PS5
    • Switch 2
    • Xbox Series
    • Switch
    • Pokemon pocket
    • FC 25 Ultimate Team
    • League of Legends
    • Tous les Forums
  • PC
  • PS5
  • Xbox Series
  • Switch 2
  • PS4
  • One
  • Switch
  • iOS
  • Android
  • MMO
  • RPG
  • FPS
En ce moment Genshin Impact Valhalla Breath of the wild Animal Crossing GTA 5 Red dead 2
Liste des sujets

Help Un virus qui supprime un antivirus

vincentdedragui
vincentdedragui
Niveau 6
15 mars 2008 à 21:29:52

Salut,
Voila depuis quelque temps j'ai un virus que je ne peut pas supprimer avec avast mais un jour ho avast disparait de la barre de tache alors je reinstalle et il est toujours pas la! je le supprime j installe kapresky et il me dit qu il peut pas s installer, ensuite j essaye bullguard il s installe mais il ne se lance pas (impossible d'executer application win32 pas valide).Apres j installe windows live onecare bug d installation, j essaye de faire un rapport avec hijachthis.exe mais il ne lance pas et me fait planter explorer.exe donc je fait Ctrl + alt + suppr pour faire executer nouvelle tache : c:/windows/explorer.exe ou un truc comme ca pour relancer l explorateur windows.
Voila j ai dit tout mes probleme sur ceux j'aimerais evité la reinstallation de windows vista trop de fichier important.
merci d avance.Veuiller m escusez pour l écriture mais j'écris vite car je suis en stress accause de ce virus

Dorian_31
Dorian_31
Niveau 18
15 mars 2008 à 21:43:43

essaie antivir

t-ka
t-ka
Niveau 8
15 mars 2008 à 21:45:47

Essaye antivir + avg

vincentdedragui
vincentdedragui
Niveau 6
15 mars 2008 à 21:51:17

j essaye et je vous dit

vincentdedragui
vincentdedragui
Niveau 6
15 mars 2008 à 21:55:37

ah oui autre chose j ai vu dans la page de telechargement que antivir etait en anglais j aimerais savoir si il existe un patch francais car moi et l'anglais ca fait 2

Dorian_31
Dorian_31
Niveau 18
15 mars 2008 à 21:57:19

non y'a pas de patch

vincentdedragui
vincentdedragui
Niveau 6
15 mars 2008 à 21:57:45

ben l installation de antivir plante ya ecrit un truc bizzard
Some files could not be created
please close all applications reboot windows and restart this installation

Dorian_31
Dorian_31
Niveau 18
15 mars 2008 à 21:59:59

mouais, ben démarre en mode sans échec et essaie d'installer comme ça, puis fait le scan toujours en mode sans échec

vincentdedragui
vincentdedragui
Niveau 6
15 mars 2008 à 22:02:01

je vais essayé et je vous dit pour le mode sans echec c'est F8 je crois non ?

Dorian_31
Dorian_31
Niveau 18
15 mars 2008 à 22:03:10

oui

anti-happiste-1
anti-happiste-1
Niveau 10
15 mars 2008 à 22:29:47

Pas la peine ton virus est bagle, tu pourras installer aucun antivirus :ok:

il faut que tu nous fasses un scan hijackthis

vincentdedragui
vincentdedragui
Niveau 6
15 mars 2008 à 23:18:30

Apres avoir installé et fait un scan avec antivir voici le raport:

AntiVir PersonalEdition Classic
Report file date: samedi 15 mars 2008 22:08

Scanning for 835736 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows Vista
Windows version: (plain) [6.0.6000]
Username: Vincent
Computer name: PC-DE-VINCENT

Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:55
ANTIVIR2.VDF : 7.0.0.1 2048 Bytes 13/09/2007 14:27:04
ANTIVIR3.VDF : 7.0.0.2 2048 Bytes 13/09/2007 14:27:13
AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 17/09/2007 17:43:56
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

Configuration settings for the scan:
Jobname..........................: Local Hard Disks
Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: samedi 15 mars 2008 22:08

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
17 processes with 17 modules were scanned

Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!

Starting to scan the registry.
The registry was scanned ( '12' files ).

Starting the file scan:

Begin scan in 'C:\' <BOOT>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Program Files\Oxin's Style!\Everlust\Oxin's Style!\Binaries\fc3DSexVillaRun.exe
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '480f40a1.qua'!

C:\Users\Vincent\AppData\Local\Microsoft\Windows\T
emporary Internet Files\Content.IE5\1MT23N05\b64_1[1].jpg
[DETECTION] Contains detection pattern of the HEUR-DBLEXT/Crypted virus
[INFO] The file was moved to '481041c1.qua'!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\B-S_Spy.zip
[0] Archive type: ZIP
--> B-S_Spy/B-S EditServer.exe
[DETECTION] Is the Trojan horse TR/BStroj.19.C
--> B-S_Spy/Msn-server.exe
[DETECTION] Is the Trojan horse TR/BStroj.19.A
--> B-S_Spy/Net-server.exe
[DETECTION] Is the Trojan horse TR/PSW.BStroj.19
--> B-S_Spy/Ya-server.exe
[DETECTION] Is the Trojan horse TR/PSW.BStroj.18
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\Fake Login Hotmail.zip
[0] Archive type: ZIP
--> Fake Login Hotmail/Hotmail.exe
[DETECTION] Is the Trojan horse TR/FakeHotmail.A.3
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\Fake MSN Messenger Version 5.0.rar
[0] Archive type: RAR
--> Fake MSN Messenger Version 5.0\fakemsn.exe
[DETECTION] Is the Trojan horse TR/PSW.MSN.Faker.E.1
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\fakeypager.zip
[0] Archive type: ZIP
--> YPager.exe
[DETECTION] Is the Trojan horse TR/PSW.Yahoo.C-Cure
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\Fake_Hotmail_Login_Screen.zip
[0] Archive type: ZIP
--> hotmailhack/001.txt
[DETECTION] Is the Trojan horse TR/Pwssnix.A
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\fmsn.zip
[0] Archive type: ZIP
--> fakemsn.exe
[DETECTION] Is the Trojan horse TR/PSW.MSN.Faker.A
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\Give me your pass v1.0.rar
[0] Archive type: RAR
--> Give me your pass v1.0\Give me your pass V1.0.exe
[DETECTION] Contains detection pattern of the construction kit KIT/PyLoard.1
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\Head Fuck Hotmail Hack.rar
[0] Archive type: RAR
--> Head Fuck Hotmail Hack\Edit Server.exe
[DETECTION] Is the Trojan horse TR/PSW.VB.DW
--> Head Fuck Hotmail Hack\hotmailhack.exe
[DETECTION] Is the Trojan horse TR/PSW.VB.EQ
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\Hotmail Hacker GOLD.rar
[0] Archive type: RAR
--> Hotmail Hacker GOLD\Hotmail Hacker GOLD.exe
[DETECTION] Contains detection pattern of the worm WORM/Hotlix
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\hotmailhack.rar
[0] Archive type: RAR
--> hotmailhack\001.txt
[DETECTION] Is the Trojan horse TR/Pwssnix.A
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\Magic Password-15-SE.rar
[0] Archive type: RAR
--> Magic Password-15-SE\MPS-15-SE.exe
[DETECTION] Is the Trojan horse TR/Spy.Delf.DD.4
--> Magic Password-15-SE\MPS-Decoder.exe
[DETECTION] Is the Trojan horse TR/Spy.Delf.DD.7
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\Msn Fake 7.rar
[0] Archive type: RAR
--> Msn Fake 7\MsnMessenger7\MSN Messenger 7.exe
[DETECTION] Is the Trojan horse TR/PSW.VB.HG
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\MSN Hacker DUC.rar
[0] Archive type: RAR
--> H0TM41LH4CK3R-DUC V.4.0.rar
[1] Archive type: RAR
--> H0TM41LH4CK3R-DUC V.4.0\H0TM41LH4CKER-DUCV.4.0(1).exe
[DETECTION] Contains detection pattern of the worm WORM/P2P.Aamd.A
--> H0TM41LH4CK3R-DUC V.4.0\H0TM41LH4CKER-DUCV.4.0(2).exe
[DETECTION] Contains detection pattern of the worm WORM/P2P.Aamd.A
--> H0TM41LH4CK3R-DUC V.4.0\H0TM41LH4CKER-DUCV.4.0(3).exe
[DETECTION] Contains detection pattern of the worm WORM/P2P.Aamd.A
--> H0TM41LH4CK3R-DUC V.4.0\H0TM41LH4CKER-DUCV.4.0.exe
[DETECTION] Contains detection pattern of the worm WORM/P2P.Aamd.A
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\MSN Spy Lite v1.0.rar
[0] Archive type: RAR
--> runtime_installer.exe
[DETECTION] Is the Trojan horse TR/Spy.Aksin
--> stub.stb
[DETECTION] Is the Trojan horse TR/Spy.VB.EI.2
--> builder.exe
[DETECTION] Is the Trojan horse TR/Spy.VB.EI.1
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\Saria Fake Logins 2.0.rar
[0] Archive type: RAR
--> Saria Fake Logins 2.0\log.php
[DETECTION] Is the Trojan horse TR/PHP.Log.1.3
--> Saria Fake Logins 2.0\Msn (Xp).exe
[DETECTION] Is the Trojan horse TR/FakeLogin.B.3
--> Saria Fake Logins 2.0\Editor.exe
[DETECTION] Is the Trojan horse TR/FakeLogin.B.1
--> Saria Fake Logins 2.0\YAHOO.exe
[DETECTION] Is the Trojan horse TR/FakeLogin.B.5
--> Saria Fake Logins 2.0\Paltalk.exe
[DETECTION] Is the Trojan horse TR/FakeLogin.B.4
--> Saria Fake Logins 2.0\Msn (9,x,me,2000).exe
[DETECTION] Is the Trojan horse TR/FakeLogin.B.2
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\XP Killer.rar
[0] Archive type: RAR
--> xpkiller.exe
[DETECTION] Is the Trojan horse TR/KillXP.A
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\XP-Killer.rar
[0] Archive type: RAR
--> XP-Killer\XP Killer.rar
[1] Archive type: RAR
--> xpkiller.exe
[DETECTION] Is the Trojan horse TR/KillXP.A
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\YAHOO Password stealer.exe
[DETECTION] Is the Trojan horse TR/PSW.Smym.A.1
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\Nuke1[1].5\nukemsn.exe
[DETECTION] Is the Trojan horse TR/Nuke.NukeMSN.14.2
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\S-H Y! Pass Sender 1.1\S_H_Yahoo_Pass_Sender.exe
[DETECTION] Is the Trojan horse TR/PSW.Delf.FG
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\YAHOO booter\boot\CBomber.exe
[DETECTION] Is the Trojan horse TR/Agent.53248.36
[INFO] The file was deleted!

C:\Users\Vincent\AppData\Local\Temp\ir_ext_temp_0\
AutoPlay\Docs\YAHOO booter\boot\KewlButtonz.ocx
[DETECTION] Contains detection pattern of a probably damaged sample CC/Agent
[INFO] The file was deleted!
C:\Windows\System32\mdelk.exe
[DETECTION] Is the Trojan horse TR/Bagle.Gen.B
[INFO] The file was deleted!
C:\Windows\System32\wintems.exe
[DETECTION] Is the Trojan horse TR/Bagle.Gen.B
[INFO] The file was deleted!
C:\Windows\System32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\Windows\System32\drivers\srosa.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was deleted!
C:\Windows\System32\drivers\down\104718.exe
[DETECTION] Is the Trojan horse TR/Bagle.Gen.B
[INFO] The file was deleted!
C:\Windows\System32\drivers\down\14840609.exe
[DETECTION] Is the Trojan horse TR/Bagle.Gen.B
[INFO] The file was deleted!
C:\Windows\System32\drivers\down\15137312.exe
[DETECTION] Is the Trojan horse TR/Bagle.Gen.B
[INFO] The file was deleted!
C:\Windows\System32\drivers\down\154531.exe
[DETECTION] Is the Trojan horse TR/Bagle.Gen.B
[INFO] The file was deleted!
C:\Windows\System32\drivers\down\331765.exe
[DETECTION] Is the Trojan horse TR/Bagle.Gen.B
[INFO] The file was deleted!
C:\Windows\System32\drivers\down\97062.exe
[DETECTION] Is the Trojan horse TR/Bagle.Gen.B
[INFO] The file was deleted!
Begin scan in 'D:\' <RECOVER>

End of the scan: samedi 15 mars 2008 23:00
Used time: 51:15 min

The scan has been done completely.

18571 Scanning directories
560401 Files were scanned
46 viruses and/or unwanted programs were found
2 Files were classified as suspicious:
31 files were deleted
0 files were repaired
2 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
560355 Files not concerned
6445 Archives were scanned
2 Warnings
3 Notes

vincentdedragui
vincentdedragui
Niveau 6
15 mars 2008 à 23:19:40

Mais je ne eput toujours pas lancer l antivirus en mode normal

Helper_PC
Helper_PC
Niveau 3
15 mars 2008 à 23:41:34

Salut,

- Télécharge ELIBAGLA en bas de cette page :
http://www.zonavirus.com/datos/descargas/95/elibagla.asp
- Clique sur le bouton Descargar Elibagla cela va télécharger le fichier, place le sur le bureau
- Double-clique dessus pour l'ouvrir
- Assure toi que dans le menu déroulant Unidad, tu as bien C:\
- Vérifies aussi que l'option en bas de la fenêtre Eliminar Ficheros Automaticamente est bien cochée
- Clique sur le bouton Explorar pour lancer l'analyse
- Enregistre le rapport et poste le ici.

vincentdedragui
vincentdedragui
Niveau 6
15 mars 2008 à 23:54:48

le raport

Sat Mar 15 23:46:21 2008
EliBagle v11.15 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle
Por favor, envienos una muestra del fichero
C:\Muestras\SROSA.SYS.Muestra EliBagle v11.15
a "virus@satinfo.es". Gracias.
C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle Acceso Denegado.
Por favor, envienos una muestra del fichero
C:\Muestras\HLDRRR.EXE.Muestra EliBagle v11.15
a "virus@satinfo.es". Gracias.
C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle Acceso Denegado.
Reinicie para Completar la Limpieza.

Sat Mar 15 23:46:57 2008
EliBagle v11.15 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
C:\Windows\System32\MDELK.EXE --> Acceso Denegado, Bagle (Reiniciar para completar la Limpieza)

Nº Total de Directorios: 18291
Nº Total de Ficheros: 125864
Nº de Ficheros Analizados: 14746
Nº de Ficheros Infectados: 1
Nº de Ficheros Limpiados: 1

Pseudo supprimé
Pseudo supprimé 16 mars 2008 à 00:04:06

le mieu c de débrancher ton disque dur, le brancher en externe sur un pc sain avec antivir ou kaspersky ou encore bitdefender, nod32

puis d'erradiquer tous les virus, puis rebrancher ton disque dur et de faire une réparation vista

vincentdedragui
vincentdedragui
Niveau 6
16 mars 2008 à 00:29:52

je vais pas demonter mon pc il est tou neuf

Dorian_31
Dorian_31
Niveau 18
16 mars 2008 à 00:41:52

hé ben, comme on dit "demerden sie sich"...

(si vous voulez savoir pourquoi je l'envoie chier, faites une recherche des topics qu'il a posté, vous comprendrez)

vincentdedragui
vincentdedragui
Niveau 6
16 mars 2008 à 09:28:50

Bon personne peut m'aider a supprimer ce bagle de merde ?

VeuveNoirinhO
VeuveNoirinhO
Niveau 10
16 mars 2008 à 10:17:53

On t'a donné la solution et tu refuses de le faire donc Dorian a raison :ok:

Sous forums
  • Aide à l'achat Mac
  • Macintosh
  • Création de Jeux
  • Programmation
  • Création de sites web
  • Linux
  • Internet
  • Steam Deck
  • Hardware
La vidéo du moment