PC très long - Page 2

Résolu
Précédent
  • 1
  • 2
  1. g3n-h@ckm@n
     
    ben non tu me l'as deja posté ^^
    0
    1. ptitcul86 Messages postés 672 Statut Membre
       
      J'ai désinstallé Google Tolbar... Tu as besoin de quoi maintenant ?
      0
  2. g3n-h@ckm@n
     
    Fais analyser le(s) fichier(s) suivants sur Virustotal :

    Virus Total

    clique sur "Parcourir" et trouve puis selectionne ce(s) fichier(s) :

    C:\Windows\system32\usbr38.dll

    * Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
    * Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
    * Lorsque l'analyse est terminée colle le lien de(s)( la) page(s) dans ta prochaine réponse.

    ===================

    ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur OTL.exe pour le lancer.

    ▶Copie la liste qui se trouve en gras ci-dessous,

    ▶ colle-la dans la zone sous "Personnalisation" :


    :processes
    explorer.exe
    iexplore.exe
    firefox.exe
    msnmsgr.exe
    Teatimer.exe

    :services
    SYMEVENT
    SYMREDRV
    SYMTDI
    42251753
    ASWMONFLT
    ASWRDR
    ASWTDI
    AVGASCLN
    AVGIDSDRIVER
    AVGIDSEH
    AVGIDSFILTER
    AVGIDSSHIM
    AVGRKX86
    AVGTDIX
    AVG_ANTI-SPYWARE_DRIVER

    :Reg
    [-HKCR\Installer\Products\B8713814E4D47A84297554B49AA067E0]
    [-HKU\S-1-5-21-3144261404-479229320-1640704271-1000\Software\YahooPartnerToolbar]
    [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\899f4ab5-8f62-4802-b90a-8b3acc21b193]
    [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\e17fe7dc-83ff-433e-a54b-7db3905387cd]
    [-HKU\S-1-5-21-3144261404-479229320-1640704271-1000\Software\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}]
    [-HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Users^propriétaire^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Notification de cadeaux MSN.lnk]
    [HKU\S-1-5-21-3144261404-479229320-1640704271-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "????r"=-
    [-HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\?????????]

    :Files
    C:\Program Files\Alwil Software
    C:\Users\propriétaire\AppData\Local\TempradABF1B.tmp
    C:\Windows\S'K

    :commands
    [CLEARALLRESTOREPOINTS]
    [emptytemp]
    [start explorer]
    [reboot]


    ▶ Clique sur "Correction" pour lancer la suppression.

    ▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.

    0
    1. ptitcul86 Messages postés 672 Statut Membre
       
      Bon, ben je ferais ça dès mardi, pour le moment je débauche. Alors je te dis très bon wee kend
      à toi ;
      0
    2. g3n-h@ckm@n
       
      ca marche :)
      0
    3. ptitcul86 Messages postés 672 Statut Membre
       
      Bonjour Gen,
      Je suis très en retard, mais je n'arrive pas à trouver dans C:\Windows\system32\usbr38.dll
      Je vois windows, puis system 32 , mais pas le reste
      0
  3. g3n-h@ckm@n
     
    hello

    la suite :)
    0
    1. ptitcul86 Messages postés 672 Statut Membre
       
      Désolée, je ne comprend pas. Quelle suite ? Je suis perdue avec ton virus total et C:\Windows\system32\usbr38.dll Explique moi en plus clair s'il te plais, merci.
      0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. g3n-h@ckm@n
     
    fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

    ▶ Télécharge ici :

    Malwarebytes

    ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

    relance malwarebytes en suivant scrupuleusement ces consignes :

    ! Déconnecte toi et ferme toutes applications en cours !

    ▶ Lance Malwarebyte's .

    Fais un examen dit "Complet" .

    ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
    ▶ à la fin tu cliques sur "résultat" .
    Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

    Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

    Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

    0
    1. ptitcul86 Messages postés 672 Statut Membre
       
      Bonjour Gen,
      Voici le rapport de malwarebyte, apparement, il n'y a pas d'infection.

      bMalwarebytes Anti-Malware 1.70.0.1100
      www.malwarebytes.org

      Version de la base de données: v2013.01.22.02

      Windows Vista Service Pack 2 x86 NTFS
      Internet Explorer 9.0.8112.16421
      propriétaire :: PC-DE-PROPRIÉTA [administrateur]

      22/01/2013 08:38:44
      mbam-log-2013-01-22 (08-38-44).txt

      Type d'examen: Examen complet (C:\|D:\|)
      Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
      Options d'examen désactivées: P2P
      Elément(s) analysé(s): 407017
      Temps écoulé: 2 heure(s), 28 minute(s), 4 seconde(s)

      Processus mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Module(s) mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Clé(s) du Registre détectée(s): 0
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre détectée(s): 0
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre détecté(s): 0
      (Aucun élément nuisible détecté)

      Dossier(s) détecté(s): 0
      (Aucun élément nuisible détecté)

      Fichier(s) détecté(s): 0
      (Aucun élément nuisible détecté)

      (fin)
      0
  6. g3n-h@ckm@n
     
    re

    bien on peut faire le menage je pense non ?
    0
    1. ptitcul86 Messages postés 672 Statut Membre
       
      Bonjour Gen,
      Dis moi le ménage qu'il faut que je fasse.
      0
  7. g3n-h@ckm@n
     
    0
    1. ptitcul86 Messages postés 672 Statut Membre
       
      RaProducts' PureRa v1.7
      Log created at 18:04 on 23/01/2013 (propriétaire)

      C:\Config.MSI emptied.
      C:\Users\propriétaire\AppData\LocalLow\Microsoft\CryptNetURLCache\Content emptied.
      C:\Users\propriétaire\AppData\LocalLow\Microsoft\CryptNetURLCache\MetaData emptied.
      C:\Windows\system32\FNTCACHE.DAT <- Le fichier spécifié est introuvable.
      Recycle bin emptied.
      C:\Windows\SoftwareDistribution\DataStore\Logs emptied.
      C:\Windows\SoftwareDistribution\Download emptied.
      C:\Windows\SoftwareDistribution\SelfUpdate\Default emptied.
      C:\Windows\SoftwareDistribution\WuRedir emptied.
      C:\Windows\SoftwareDistribution\ReportingEvents.log <- Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
      C:\Users\PROPRI~1\AppData\Local\Temp emptied.
      C:\Windows\TEMP emptied.

      Total space cleaned: 0 bytes

      -=E.O.F=-
      0
    2. g3n-h@ckm@n
       
      t'es sur d'avoir bien suivi la config pour purera ?
      0
    3. ptitcul86 Messages postés 672 Statut Membre
       
      Bonjour Gen,
      J'avais tout simplement oublié de cocher la case '' Uncheck all ''

      RaProducts' PureRa v1.7
      Log created at 08:15 on 24/01/2013 (propriétaire)

      C:\Config.MSI emptied.
      C:\Users\propriétaire\AppData\LocalLow\Microsoft\CryptNetURLCache\Content emptied.
      C:\Users\propriétaire\AppData\LocalLow\Microsoft\CryptNetURLCache\MetaData emptied.
      C:\Windows\system32\FNTCACHE.DAT <- Successfully deleted.
      Recycle bin emptied.
      C:\Windows\SoftwareDistribution\DataStore\Logs emptied.
      C:\Windows\SoftwareDistribution\Download emptied.
      C:\Windows\SoftwareDistribution\SelfUpdate\Default emptied.
      C:\Windows\SoftwareDistribution\WuRedir emptied.
      C:\Windows\SoftwareDistribution\ReportingEvents.log <- Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
      C:\Users\PROPRI~1\AppData\Local\Temp emptied.
      C:\Windows\TEMP emptied.
      C:\ProgramData\Microsoft\Windows\Sqm\Upload\Global_13238528_00.sqm <- Successfully deleted.
      C:\ProgramData\Microsoft\Windows\Sqm\Upload\Global_13238784_00.sqm <- Successfully deleted.
      C:\ProgramData\Microsoft\Windows\Sqm\Upload\Private_142593_00.sqm <- Successfully deleted.
      C:\ProgramData\Microsoft\Windows\Sqm\Upload\Private_142593_01.sqm <- Successfully deleted.
      C:\ProgramData\Microsoft\Windows\Sqm\Upload\Private_142593_02.sqm <- Successfully deleted.
      C:\ProgramData\Microsoft\Windows\Sqm\Upload\Private_142593_03.sqm <- Successfully deleted.
      C:\ProgramData\Microsoft\Windows\Sqm\Upload\Private_591363_00.sqm <- Successfully deleted.
      C:\ProgramData\Microsoft\Windows\Sqm\Upload\Private_592388_00.sqm <- Successfully deleted.
      C:\ProgramData\Microsoft\Windows\Sqm\Upload\Private_592388_01.sqm <- Successfully deleted.
      C:\ProgramData\Microsoft\Windows\Sqm\Upload\Private_592388_02.sqm <- Successfully deleted.
      C:\Users\propriétaire\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db <- Successfully deleted.
      C:\Users\propriétaire\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db <- Successfully deleted.
      C:\Users\propriétaire\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db <- Successfully deleted.
      C:\Users\propriétaire\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db <- Successfully deleted.
      C:\Users\propriétaire\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db <- Successfully deleted.
      C:\Users\propriétaire\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db <- Successfully deleted.
      C:\Users\propriétaire\AppData\Local\Microsoft\Windows Live\SqmApi\SqmData21_00.sqm <- Successfully deleted.
      C:\Users\propriétaire\AppData\Roaming\Microsoft\MSN Messenger\sqmdata00.sqm <- Successfully deleted.
      C:\Users\propriétaire\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt00.sqm <- Successfully deleted.

      Total space cleaned: 3.35 MB

      -=E.O.F=-
      0
    4. ptitcul86 Messages postés 672 Statut Membre
       
      Dois je garder '' Slowin killer '' sur le bureau ?
      0
  8. g3n-h@ckm@n
     
    bah si tatoufé oué ^^
    0
    1. ptitcul86 Messages postés 672 Statut Membre
       
      Bon, ben je tiens à te remercier encore une fois de m'avoir aidé. J'espère que je vais être tranquille un bon moment. De toutes façons, je sais à qui m'adresser, car vous êtes plusieurs à m'avoir déjà aidé, vous êtes supers. Alors à une prochaine fois, et encore, grand merci à toi. Très bonne continuation.
      0
    2. g3n-h@ckm@n
       
      itou :)

      tu peux mettre le sujet en resolu si tu veux ^^
      0
  9. weakiz Messages postés 116 Statut Membre 25
     
    Plusieurs solutions :

    - nettoyer votre PC avec un logiciel de type Ccleaner
    - débarrasser vous des tous vos malware avec le logiciel Spybot search and destroy
    - analyse antivirus
    - si vous avez un pc fixe peut-être même qu'il contient beaucoup de poussière => nettoyez-le à l'intérieur (pas de lingette, ne pas le rendre humide, moi personnelement je nettoie tout ça avec une pompe à vélo à la "McGyver")

    Je suis sur et certain qu'en suivant bien ces conseils votre pc va retrouver une seconde vie

    -5
    1. ptitcul86 Messages postés 672 Statut Membre
       
      Et bien je fais tous ça 1 fois par semaine, mais là il est très mou
      0
Précédent
  • 1
  • 2