Est ce que je suis piraté ou non ?!
Résolu/Fermé
supupoff
Messages postés
350
Statut
Membre
-
g3n-h@ckm@n -
g3n-h@ckm@n -
Salut,
Comment assurer que mon PC n'est pas piraté ?!! merci d'avance
Comment assurer que mon PC n'est pas piraté ?!! merci d'avance
12 réponses
-
et ouais t'es pourri de keygens comment tu veux avoir un pc qui tourne rond ?et en plus t'as rien supprimé selon le rapport
-
-
Attention : cet outil peut etre détecté à tort comme virus
tous les processus "non vitaux de windows" vont être coupés , enregistre ton travail.
Désactive toutes tes protections si possible , antivirus , sandbox , etc....
telecharge et enregistre Pre_Scan sur ton bureau :
http://forums-fec.be/gen-hackman/Pre_Scan.exe
http://general-changelog-team.fr/fr/downloads/viewdownload/41-outils-de-gen-hackman/52-pre-scan
Avertissement :Il y aura une extinction du bureau pendant le scan --> pas de panique.
une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan_la_date_et_l'heure.txt" sur le bureau.
si l'outil est relancé plusieurs fois , il te proposera un menu et qu'aucune option n'est demandée, lance l'option "Kill"
si l'outil est bloqué par l'infection utilise cette version avec extension .pif :
http://forums-fec.be/gen-hackman/Pre_Scan.pif
si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"
Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler
Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan
Il est possible que l'outil fasse redemarrer ton pc plusieurs fois , laisse-le faire
NE LE POSTE PAS SUR LE FORUM !!! (il est trop long)
Heberge le rapport sur http://pjjoint.malekal.com puis donne le lien obtenu en echange sur le forum où tu te fais aider-
Merci beaucoup :))
le rapport
https://pjjoint.malekal.com/files.php?read=20120803_e7j10o13h8n13
RQ : cet outil a créer un dossier autorun.inf dans chaqu'une de partition !!
-
-
nan pre_scan ne vaccine pas c'est le travail d'usbfix ca :)
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
je regarde ton rapport :) -
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question -
internet explorer à mettre à jour
chrome à mettre à jour
==
t'as pas desactivé antivir !!! carton rouge !! ^^
[MD5.E491888D529410D7BD8FBBAD825795C8] - [10/06/2012 16:34:59] - 1540 | C:\Program Files\Avira\AntiVir Desktop\avguard.exe (.Avira Operations GmbH & Co. KG - Avira On-Access Service.) - (12.1.0.18) -> "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [110032 Ko]
faut fermer le parapluie dans la barre des taches
==
Clique sur ce lien : https://www.cjoint.com/?BHdleSBCunJ
Selectionne tout le texte qui s'y trouve CTRL+A puis CTRL+C ou clic droit/copier
Relance Pre_scan puis choisis l'option "Script"
une page va s'ouvrir
logiquement le texte que tu as sélectionné s'y trouve déjà , donc tu fermes et le programme va travailler.
sinon colle-le (clic droit/coller ou ctrl+V) dans la page vierge.
puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte
des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille
poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan_Concept ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
ne gardez pas les outils de desinfection dans le pc , ils sont mis à jour tous les jours -
-
ok je connizas pas ^^
==
fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
▶ Télécharge ici :
Malwarebytes
▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
▶ Lance Malwarebyte's .
Fais un examen dit "Complet" .
▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
▶ à la fin tu cliques sur "résultat" .
▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
-
Hello,
As-tu déjà fait un scan complet de ton disque dur à l'aide de ton antivirus ? -
Pour repondre à ta question il nous faudrait des renseignements :
Systeme ?
qu'est ce qui te fait croire que tu as ete piraté ?
antivirus ?
etc...
ma boule de crystal est en panne !!! -
-
Cette astuce que pour Windows xp & 2000:
Menu démarre >>> Exécuter >>> System.ini >>> Ok
Un bloc note qui s'affiche tu trouves
; for 16-bit app support
[drivers]
wave=mmdrv.dll
timer=timer.drv
[mci]
[driver32]
[386enh]
Donc ton pc n'est pas piraté ou étais piraté.
si tu trouves dans ton bloc note:
********** for 16-bit app support
[drivers]
wave=mmdrv.dll
timer=timer.drv
[mci]
[driver32]
[386enh]
Ben ton pc et déjà piraté -
▶ Téléchargez UsbFix (créé par El Desaparecido) sur votre Bureau.
▶ Si votre antivirus affiche une alerte, ignorez-la et désactivez l'antivirus temporairement.
▶ Branchez toutes vos sources de données externes à votre PC (clé USB, disque dur externe, etc...) sans les ouvrir.
▶ Double cliquez sur UsbFix.exe.
▶ Cliquez sur Suppression.
▶ Laissez travailler l'outil.
▶ À la fin du scan, un rapport va s'afficher, postez-le dans votre prochaine réponse sur le forum.
▶ Le rapport est aussi sauvegardé à la racine du disque système ( C:\UsbFix.txt ).
▶ Tutoriel vidéo
-
Merci :))
voila le rapport :
----------------
############################## | UsbFix V 7.094 | [Suppression]
Utilisateur: Ila (Administrateur) # ILA-PC
Mis à jour le 20/07/2012 par El Desaparecido
Lancé à 07:38:37 | 03/08/2012
Site Web: https://www.sosvirus.net/
Forum: http://forum.eldesaparecido.com
Fichier suspect ? : http://eldesaparecido.com/upload.php
Contact: contact@eldesaparecido.com
PC: TOSHIBA (Satellite L350) (X86-based PC) # Notebook
CPU: Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz (2166)
RAM -> [Total : 2940 | Free : 1760]
BIOS: InsydeH2O Version 2.20
BOOT: Normal boot
OS: Microsoft Windows 7 Edition Intégrale (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 8.0.7601.17514
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Avira Desktop [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 55 Go (13 Go libre(s) - 24%) [Systeme :D] # NTFS
D:\ -> Disque fixe # 110 Go (31 Go libre(s) - 29%) [MyDocs :p] # NTFS
E:\ -> Disque fixe # 68 Go (20 Go libre(s) - 29%) [MyWorld :)] # NTFS
F:\ -> CD-ROM
I:\ -> CD-ROM
################## | Processus Actif |
C:\Windows\system32\csrss.exe (336)
C:\Windows\system32\wininit.exe (392)
C:\Windows\system32\csrss.exe (404)
C:\Windows\system32\services.exe (448)
C:\Windows\system32\lsass.exe (480)
C:\Windows\system32\lsm.exe (488)
C:\Windows\system32\winlogon.exe (496)
C:\Windows\system32\svchost.exe (644)
C:\Windows\system32\svchost.exe (728)
C:\Windows\System32\svchost.exe (776)
C:\Windows\System32\svchost.exe (856)
C:\Windows\system32\svchost.exe (888)
C:\Windows\system32\svchost.exe (1072)
C:\Windows\System32\svchost.exe (1208)
C:\Windows\system32\svchost.exe (1336)
C:\Windows\System32\spoolsv.exe (1412)
C:\Program Files\Avira\AntiVir Desktop\sched.exe (1440)
C:\Program Files\Avira\AntiVir Desktop\avguard.exe (1540)
C:\ProgramData\Dim@net\OnlineUpdate\ouc.exe (1668)
C:\ProgramData\DatacardService\HWDeviceService.exe (1680)
C:\Windows\system32\taskhost.exe (1812)
C:\Windows\system32\Dwm.exe (1900)
C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (1960)
C:\Windows\Explorer.EXE (2008)
C:\ProgramData\DatacardService\DCSHelper.exe (2036)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (884)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (1264)
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (2052)
C:\Program Files\Internet Download Manager\IDMan.exe (2072)
C:\Program Files\alquds\alquds.exe (2080)
C:\Program Files\AutoScreenShot\AutoScreenShot.exe (2088)
C:\ProgramData\DatacardService\DCSHelper.exe (2224)
C:\Program Files\Dim@net\Dim@net.exe (2276)
C:\Program Files\Internet Download Manager\IEMonitor.exe (2360)
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (2936)
C:\Windows\system32\conhost.exe (2948)
C:\Windows\system32\SearchIndexer.exe (3020)
C:\Windows\system32\WUDFHost.exe (3140)
C:\Program Files\Mozilla Firefox\firefox.exe (3448)
C:\Windows\system32\SearchProtocolHost.exe (3536)
C:\Windows\system32\svchost.exe (3696)
C:\Program Files\Mozilla Firefox\plugin-container.exe (3292)
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe (3348)
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe (3364)
C:\Windows\System32\svchost.exe (2392)
C:\Windows\system32\taskeng.exe (3444)
C:\Windows\system32\SearchFilterHost.exe (1692)
C:\Program Files\Internet Explorer\IELowutil.exe (1200)
C:\UsbFix\Go.exe (2704)
C:\Windows\system32\wbem\wmiprvse.exe (3440)
C:\Windows\system32\DllHost.exe (2448)
################## | Processus Stoppés |
Stoppé! C:\Windows\System32\spoolsv.exe (1412)
Stoppé! C:\Program Files\Avira\AntiVir Desktop\sched.exe (1440)
Stoppé! C:\Program Files\Avira\AntiVir Desktop\avguard.exe (1540)
Stoppé! C:\ProgramData\Dim@net\OnlineUpdate\ouc.exe (1668)
Stoppé! C:\ProgramData\DatacardService\HWDeviceService.exe (1680)
Stoppé! C:\Windows\system32\taskhost.exe (1812)
Stoppé! C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (1960)
Stoppé! C:\ProgramData\DatacardService\DCSHelper.exe (2036)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (884)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (1264)
Stoppé! C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (2052)
Stoppé! C:\Program Files\Internet Download Manager\IDMan.exe (2072)
Stoppé! C:\Program Files\alquds\alquds.exe (2080)
Stoppé! C:\Program Files\AutoScreenShot\AutoScreenShot.exe (2088)
Stoppé! C:\ProgramData\DatacardService\DCSHelper.exe (2224)
Stoppé! C:\Program Files\Dim@net\Dim@net.exe (2276)
Stoppé! C:\Program Files\Internet Download Manager\IEMonitor.exe (2360)
Stoppé! C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (2936)
Stoppé! C:\Windows\system32\conhost.exe (2948)
Stoppé! C:\Windows\system32\SearchIndexer.exe (3020)
Stoppé! C:\Windows\system32\WUDFHost.exe (3140)
Stoppé! C:\Program Files\Mozilla Firefox\firefox.exe (3448)
Stoppé! C:\Windows\system32\SearchProtocolHost.exe (3536)
Stoppé! C:\Program Files\Mozilla Firefox\plugin-container.exe (3292)
Stoppé! C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe (3348)
Stoppé! C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe (3364)
Stoppé! C:\Windows\system32\taskeng.exe (3444)
Stoppé! C:\Windows\system32\SearchFilterHost.exe (1692)
Stoppé! C:\Program Files\Internet Explorer\IELowutil.exe (1200)
################## | Eléments infectieux |
Non supprimé ! I:\AutoRun.exe
Non supprimé ! I:\AutoRun.exe
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-3749629308-3875714456-389648346-1000
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-1173741899-700605087-3523865979-1000
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-3460173620-2617874386-4048651164-1000
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-3749629308-3875714456-389648346-1000
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-4210323189-462073642-3176805670-1000
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-715996393-1462182584-2555354105-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-1173741899-700605087-3523865979-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-1484579147-3130951888-2963976229-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-1691214071-2026547033-2313173215-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-201857047-3786966675-225439498-1001
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-201857047-3786966675-225439498-1005
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-3132689417-2636423653-3493171034-1001
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-3460173620-2617874386-4048651164-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-3749629308-3875714456-389648346-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-3938454661-3782296209-1652901042-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-3956480493-171730094-3382910513-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-4210323189-462073642-3176805670-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-715996393-1462182584-2555354105-1000
Supprimé! E:\Recycler\S-1-5-21-1659004503-606747145-1801674531-1003
Supprimé! E:\Recycler\S-1-5-21-1708537768-1454471165-682003330-1003
Supprimé! E:\Recycler\S-1-5-21-1708537768-651377827-1417001333-1003
Supprimé! E:\Recycler\S-1-5-21-1935655697-1645522239-1417001333-1003
Supprimé! E:\Recycler\S-1-5-21-1960408961-1220945662-1801674531-1003
Supprimé! E:\Recycler\S-1-5-21-448539723-1343024091-1417001333-1003
Supprimé! D:\khawla
Non supprimé ! I:\AUTORUN.INF
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Mountpoints2 |
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\I
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{0b741519-d099-11e1-8e38-001e101fe5e1}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a80be68f-da5c-11e1-97de-001e33a11d9a}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{c2fcd378-c65e-11e1-931e-001e101f50a4}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{c2fcd394-c65e-11e1-931e-001e101f50a4}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{ca512797-b30d-11e1-b77b-001e33a11d9a}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{ca5127cc-b30d-11e1-b77b-001e33a11d9a}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{d14a76d9-b47c-11e1-a03a-001e33a11d9a}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{e29e1f95-c40a-11e1-8bc9-001e101f8924}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{e29e1fad-c40a-11e1-8bc9-001e101f8924}
################## | Listing |
[03/08/2012 - 07:47:11 | SHD ] C:\$Recycle.Bin
[10/06/2009 - 22:42:20 | N | 24] C:\autoexec.bat
[10/06/2012 - 16:59:46 | SHD ] C:\Boot
[20/11/2010 - 22:29:06 | RASH | 383786] C:\bootmgr
[10/06/2012 - 16:59:49 | N | 8192] C:\BOOTSECT.BAK
[10/06/2009 - 22:42:20 | N | 10] C:\config.sys
[14/07/2009 - 05:53:55 | SHD ] C:\Documents and Settings
[03/08/2012 - 07:29:16 | ASH | 2312105984] C:\hiberfil.sys
[11/06/2012 - 19:14:40 | N | 0] C:\IO.SYS
[11/06/2012 - 19:14:40 | N | 0] C:\MSDOS.SYS
[10/06/2012 - 16:19:54 | RHD ] C:\MSOCache
[03/08/2012 - 07:29:19 | ASH | 3082809344] C:\PAGEFILE.SYS
[14/07/2009 - 03:37:05 | D ] C:\PerfLogs
[02/08/2012 - 19:19:59 | D ] C:\Program Files
[02/08/2012 - 04:17:54 | HD ] C:\ProgramData
[17/06/2012 - 10:39:20 | D ] C:\PS11.0.1
[10/06/2012 - 16:13:49 | SHD ] C:\Recovery
[02/08/2012 - 17:06:06 | SHD ] C:\System Volume Information
[03/08/2012 - 07:47:12 | D ] C:\UsbFix
[03/08/2012 - 07:38:33 | A | 9333] C:\UsbFix.txt
[10/06/2012 - 16:14:00 | D ] C:\Users
[23/07/2012 - 16:41:56 | D ] C:\Windows
[03/08/2012 - 07:47:12 | SHD ] D:\$RECYCLE.BIN
[18/06/2012 - 16:40:19 | D ] D:\Big-Mas
[15/06/2012 - 11:59:01 | D ] D:\COran
[15/04/2012 - 23:54:55 | D ] D:\cours_prof
[30/07/2012 - 20:50:46 | D ] D:\Downloads
[23/07/2012 - 13:22:05 | D ] D:\ISO
[08/06/2012 - 21:01:41 | D ] D:\Issa
[26/07/2012 - 17:03:28 | D ] D:\logiciel
[14/04/2012 - 10:01:34 | D ] D:\Master Collection Adobe.CS4
[22/06/2012 - 22:58:02 | D ] D:\Needed
[27/10/2011 - 20:01:53 | N | 34577] D:\Programme+Mastère.pdf
[20/02/2012 - 11:45:22 | SHD ] D:\System Volume Information
[03/08/2012 - 07:47:12 | SHD ] E:\$RECYCLE.BIN
[23/07/2012 - 13:24:04 | D ] E:\Adobe
[15/07/2012 - 07:50:44 | D ] E:\CV_Lettre
[22/05/2012 - 23:33:40 | D ] E:\Docs_Ali
[23/07/2012 - 13:24:04 | D ] E:\DriverPC
[23/07/2012 - 13:24:24 | D ] E:\formation
[01/01/2012 - 08:16:09 | D ] E:\Islame
[28/04/2012 - 15:34:42 | D ] E:\log-graya
[16/01/2012 - 00:00:23 | D ] E:\ma blue
[08/09/2011 - 15:07:57 | D ] E:\Mariage-Mongi-(2&3-9-2011)
[21/06/2012 - 08:59:29 | D ] E:\montage-pc
[23/07/2012 - 13:28:27 | D ] E:\Multimédia_Formation
[03/08/2012 - 07:42:35 | SHD ] E:\RECYCLER
[20/02/2012 - 23:49:07 | SHD ] E:\System Volume Information
[16/01/2012 - 00:00:23 | D ] E:\Toshiba__
[15/04/2012 - 14:49:22 | D ] E:\Utilitaire_Windows
[31/12/2011 - 21:01:36 | D ] E:\Znd-Framework et MVC
[15/01/2012 - 23:59:35 | D ] E:\????????
[19/03/2011 - 00:27:22 | R | 148320] I:\AutoRun.exe
[20/10/2008 - 18:12:34 | R | 45] I:\AUTORUN.INF
[06/01/2012 - 09:07:22 | D ] I:\Dim@net
[21/01/2011 - 10:34:16 | R | 25214] I:\Startup.ico
[30/12/2011 - 13:23:16 | R | 1579] I:\SysConfig.dat
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
-