Comprendre le rapport RogueKiller

Après avoir télécharger RogueKiller depuis le site: https://www.luanagames.com/index.fr.html
et suivre les étapes qu'il faut, voilà le rapport:

RogueKiller V5.2.2 [05/06/2011] par Tigzy
contact sur https://www.luanagames.com/index.fr.html
mail: tigzyRK<at>gmail<dot>com
Remontees: https://www.luanagames.com/index.fr.html

Systeme d'exploitation: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Demarrage : Mode normal
Utilisateur: user [Droits d'admin]
Mode: Suppression -- Date : 15/06/2011 12:58:01

Processus malicieux: 3
[SUSP PATH] PLFSetI.exe -- c:\windows\plfseti.exe -> KILLED
[SUSP PATH] lsnfier.exe -- c:\users\user\appdata\roaming\microsoft\notification de cadeaux msn\lsnfier.exe -> KILLED
[SUSP PATH] jvu.exe -- c:\users\user\appdata\local\jvu.exe -> KILLED

Entrees de registre: 12
[SUSP PATH] HKCU\[...]\Run : biecei (C:\Users\user\biecei.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : PLFSetI (C:\Windows\PLFSetI.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : RestartNeroSetup ("C:\Users\user\AppData\Local\Temp\NERO13823\setupx.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : adiras (C:\Windows\adiras.exe) -> DELETED
[SUSP PATH] Notification de cadeaux MSN.lnk : C:\Users\user\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe -> DELETED
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[FILE ASSO] HKCU\[...]Software\Classes\.exe\shell\open\command : ("C:\Users\user\AppData\Local\jvu.exe" -a "%1" %*) -> REPLACED : ("%1" %*)
[FILE ASSO] HKCU\[...]Software\Classes\exefile\shell\open\command : ("C:\Users\user\AppData\Local\jvu.exe" -a "%1" %*) -> REPLACED : ("%1" %*)
[FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command : ("C:\Users\user\AppData\Local\jvu.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") -> REPLACED : ("C:\Program Files\mozilla firefox\firefox.exe")
[FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command : ("C:\Users\user\AppData\Local\jvu.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) -> REPLACED : ("C:\Program Files\mozilla firefox\firefox.exe" -safe-mode)
[FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command : ("C:\Users\user\AppData\Local\jvu.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") -> REPLACED : ("C:\Program Files\internet explorer\iexplore.exe")

Fichier HOSTS:
127.0.0.1 localhost
::1 localhost
127.0.0.1 localhost

Termine : << RKreport[1].txt >>
RKreport[1].txt

109 réponses

Résumé de la discussion

L'objet analyse un rapport RogueKiller sur Windows Vista 32 bits, détaillant des processus malicieux et des entrées de registre modifiées ainsi que des modifications de liaisons et d'associations de fichiers. Plusieurs réponses proposent des solutions, notamment une restauration système et des procédures techniques utilisant CFScript/ComboFix pour nettoyer les éléments détectés après l'analyse et stabiliser l'ordinateur. D'autres échanges évoquent des vérifications comme VirusTotal et des analyses avec OTL, ou des scripts pré-script pour détecter des éléments persistants, tout en évoquant des risques liés à l'emploi d'outils non officiels. Des mentions soulignent aussi que des solutions suggérées touchent des systèmes piratés et des questions de réparation, apportant une dimension de sécurité et de prudence.

Bobot (l’IA à votre service)
  1. salut as-tu des fichiers / dossiers cachés dans ton menu demarrer ou dans tes documents?
    0
    1. fais l'option 6 de roguekiller et poste le rapport
      0
      1. Au fait pour les dossiers cachés je les ai sur D
        0
        1. en tout cas voilà le rapport:

          RogueKiller V5.2.2 [05/06/2011] par Tigzy
          contact sur https://www.luanagames.com/index.fr.html
          mail: tigzyRK<at>gmail<dot>com
          Remontees: https://www.luanagames.com/index.fr.html

          Systeme d'exploitation: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
          Demarrage : Mode normal
          Utilisateur: user [Droits d'admin]
          Mode: Raccourcis RAZ -- Date : 15/06/2011 16:12:32

          Processus malicieux: 4
          [SUSP PATH] winlogon.exe -- c:\users\user\appdata\local\winlogon.exe -> KILLED
          [SUSP PATH] services.exe -- c:\users\user\appdata\local\services.exe -> KILLED
          [SUSP PATH] lsass.exe -- c:\users\user\appdata\local\lsass.exe -> KILLED
          [SUSP PATH] inetinfo.exe -- c:\users\user\appdata\local\inetinfo.exe -> KILLED

          Attributs de fichiers restaures:
          Bureau: Success 2 / Fail 0
          Lancement rapide: Success 0 / Fail 0
          Programmes: Success 272 / Fail 0
          Menu demarrer: Success 3 / Fail 0
          Dossier utilisateur: Success 429 / Fail 0
          Mes documents: Success 10 / Fail 0
          Mes favoris: Success 0 / Fail 0
          Mes images: Success 0 / Fail 0
          Ma musique: Success 8 / Fail 0
          Mes videos: Success 0 / Fail 0
          Disques locaux: Success 494 / Fail 0
          Sauvegarde: [NOT FOUND]

          Lecteurs:
          [C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
          [D:] \Device\HarddiskVolume3 -- 0x3 --> Restored
          [E:] \Device\CdRom0 -- 0x5 --> Skipped

          Termine : << RKreport[2].txt >>
          RKreport[1].txt ; RKreport[2].txt
          0
          1. desactive ton antivirus
            desactive Windows defender si présent
            desactive ton pare-feu

            Ferme toutes tes appilications en cours

            telecharge et enregistre ceci sur ton bureau :

            Pre_Scan

            s'il n'est pas sur ton bureau coupe-le de ton dossier telechargements et colle-le sur ton bureau

            Avertissement: Il y aura une extinction courte du bureau --> pas de panique.

            une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan.txt" sur le bureau.

            si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

            si l'outil semble ne pas avoir fonctionné renomme-le winlogon , ou change son extension en .com ou .scr

            Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

            Poste Pre_Scan.txt qui apparaitra sur le bureau en fin de scan

            ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

            clique sur ce lien : http://www.cijoint.fr/

            ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

            ▶ Clique sur Ouvrir.

            ▶ Clique sur "Cliquez ici pour déposer le fichier".

            Un lien de cette forme :

            http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

            est ajouté dans la page.

            ▶ Copie ce lien dans ta réponse.
            0
            1. J'ai lancé Pre_scan, Il y a eu une extinction courte du bureau, les fenêtres noires qui clignotent aussi
              mais après mon ordi a signalé une erreur (une page bleue) et il a redémarré
              après quand quand il a redémarré il y a eu une petite notification qui dit que les programmes malveillants ont été partiellement supprimés et il me demande si je veux terminer la suppression.
              alors quoi faire mnt ??
              0
              1. Pre_scan.txt n'a pas été créer sur le bureau, c normal puisqu'il y a eu un interruption
                0
                1. Exactement, le fichier Pre_scan existe dans C:\ =)
                  le voilà:

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan 1.0.2.13 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                  ¤¤¤¤¤ XP | Vista | Seven - 32/64 bits ¤¤¤¤¤

                  Mis à jour le 15/06/2011 | 12.30 par g3n-h@ckm@n
                  Utilisateur : user (Administrateurs)
                  Ordinateur : LAMIAE

                  Système d'exploitation : Windows Vista (TM) Home Premium (32 bits) HomePremium Service Pack 1
                  Enregistré sous : user
                  Processeur : Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
                  Identification : x86 Family 6 Model 23 Stepping 10
                  Internet Explorer : 8.0.6001.19048
                  Mozilla Firefox : 4.0.1 (fr)
                  Pare-feu windows : Actif
                  Windows Defender : Inactif

                  Scan : 16:31:21 | 15/06/2011

                  ¤¤¤¤¤¤¤¤¤¤ Sessions

                  [HKLM | ProfileList] | S-1-5-21-3616354201-1143711275-3927985168-1000 : ProfileImagePath -> C:\Users\user
                  [HKLM | ProfileList] | S-1-5-21-3616354201-1143711275-3927985168-1000 : RefCount -> 6
                  [HKLM | ProfileList] | S-1-5-21-3616354201-1143711275-3927985168-1000 : State -> 0

                  ¤¤¤¤¤¤¤¤¤¤ Verification des Fichiers

                  C:\Windows\System32\compcln.exe........absent !!!!
                  C:\Windows\System32\compcln.exe........Impossible de télécharger le fichier , non replacé !!!!

                  C:\Windows\System32\DevicePairingWizard.exe........absent !!!!
                  C:\Windows\System32\DevicePairingWizard.exe........Impossible de télécharger le fichier , non replacé !!!!

                  C:\Windows\System32\IasMigReader.exe........absent !!!!
                  C:\Windows\System32\IasMigReader.exe........Impossible de télécharger le fichier , non replacé !!!!

                  C:\Windows\System32\spinstall.exe........absent !!!!
                  C:\Windows\System32\spinstall.exe........Impossible de télécharger le fichier , non replacé !!!!

                  C:\Windows\System32\spreview.exe........absent !!!!
                  C:\Windows\System32\spreview.exe........Impossible de télécharger le fichier , non replacé !!!!

                  ¤¤¤¤¤¤¤¤¤¤¤ Processus en cours

                  Demarrage : Normal

                  460 | C:\Windows\System32\smss.exe - SYSTEM - Normal - \SystemRoot\System32\smss.exe - 4
                  604 | C:\Windows\system32\csrss.exe - SYSTEM - Normal - C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 - 592
                  648 | C:\Windows\system32\wininit.exe - SYSTEM - High - wininit.exe - 592
                  660 | C:\Windows\system32\csrss.exe - SYSTEM - Normal - C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 - 640
                  700 | C:\Windows\system32\services.exe - SYSTEM - Normal - C:\Windows\system32\services.exe - 648
                  712 | C:\Windows\system32\lsass.exe - SYSTEM - Normal - C:\Windows\system32\lsass.exe - 648
                  724 | C:\Windows\system32\lsm.exe - SYSTEM - Normal - C:\Windows\system32\lsm.exe - 648
                  808 | C:\Windows\system32\winlogon.exe - SYSTEM - High - winlogon.exe - 640
                  920 | C:\Windows\system32\svchost.exe - SYSTEM - Normal - C:\Windows\system32\svchost.exe -k DcomLaunch - 700
                  984 | C:\Windows\system32\svchost.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\svchost.exe -k rpcss - 700
                  1052 | C:\Windows\System32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - 700
                  1132 | C:\Windows\System32\svchost.exe - SYSTEM - Normal - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - 700
                  1160 | C:\Windows\system32\svchost.exe - SYSTEM - Normal - C:\Windows\system32\svchost.exe -k netsvcs - 700
                  1296 | C:\Windows\system32\svchost.exe - SYSTEM - Normal - C:\Windows\system32\svchost.exe -k GPSvcGroup - 700
                  1324 | C:\Windows\system32\SLsvc.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\SLsvc.exe - 700
                  1372 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k LocalService - 700
                  1512 | C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe - SYSTEM - Normal - "C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe" - 1084
                  1572 | C:\Windows\system32\svchost.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\svchost.exe -k NetworkService - 700
                  1788 | C:\Windows\System32\spoolsv.exe - SYSTEM - Normal - C:\Windows\System32\spoolsv.exe - 700
                  1820 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork - 700
                  1988 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k bthsvcs - 700
                  2024 | C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe - SYSTEM - Normal - "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe" - 700
                  236 | C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe - SYSTEM - Normal - "C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe" - 700
                  292 | C:\Program Files\Common Files\DeviceHelper\DeviceManager.exe - SYSTEM - Normal - "C:\Program Files\Common Files\DeviceHelper\DeviceManager.exe" -start - 700
                  332 | C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe - SYSTEM - Normal - "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe" - 700
                  968 | C:\Program Files\Acer\Empowering Technology\Service\ETService.exe - SYSTEM - Normal - "C:\Program Files\Acer\Empowering Technology\Service\ETService.exe" - 700
                  1508 | C:\Program Files\Acer\Acer Bio Protection\BASVC.exe - SYSTEM - Normal - "C:\Program Files\Acer\Acer Bio Protection\BASVC.exe" - 700
                  1668 | C:\Program Files\Common Files\LightScribe\LSSrvc.exe - SYSTEM - Normal - "C:\Program Files\Common Files\LightScribe\LSSrvc.exe" - 700
                  2032 | C:\Windows\system32\lkads.exe - SYSTEM - Normal - C:\Windows\system32\lkads.exe - 700
                  2016 | C:\Windows\system32\lktsrv.exe - SYSTEM - Normal - C:\Windows\system32\lktsrv.exe - 700
                  384 | C:\Acer\Mobility Center\MobilityService.exe - SYSTEM - Normal - "C:\Acer\Mobility Center\MobilityService.exe" -p - 700
                  284 | C:\Program Files\National Instruments\MAX\nimxs.exe - SYSTEM - Normal - "C:\Program Files\National Instruments\MAX\nimxs.exe" - 700
                  2076 | C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe - SYSTEM - Normal - "C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe" - 700
                  2224 | C:\Windows\system32\nipalsm.exe - SYSTEM - Normal - C:\Windows\system32\nipalsm.exe - 700
                  2260 | C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe - SYSTEM - Normal - "C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe" - 700
                  2300 | C:\Windows\system32\nisvcloc.exe - SYSTEM - Normal - C:\Windows\system32\nisvcloc.exe -s - 700
                  2376 | C:\Windows\system32\taskeng.exe - SYSTEM - Below Normal - taskeng.exe {94EF75DC-A004-433A-9177-1546B3A4CB93} - 1160
                  2416 | C:\Windows\system32\Dwm.exe - user - High - "C:\Windows\system32\Dwm.exe" - 1132
                  2472 | C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe - SYSTEM - Normal - "C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe" - 700
                  2508 | C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe - SYSTEM - Normal - "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe" - 700
                  2564 | C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe - SYSTEM - Normal - "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe" - 700
                  2616 | C:\Windows\system32\svchost.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted - 700
                  2640 | c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe - SYSTEM - Normal - "c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" - 700
                  2752 | C:\Program Files\Cyberlink\Shared files\RichVideo.exe - SYSTEM - Normal - "C:\Program Files\Cyberlink\Shared files\RichVideo.exe" - 700
                  2796 | C:\Windows\system32\taskeng.exe - user - Normal - taskeng.exe {94F68C75-B3EF-472A-BAC4-2862994403D8} - 1160
                  2820 | C:\Program Files\Acer\Acer VCM\RS_Service.exe - SYSTEM - Normal - "C:\Program Files\Acer\Acer VCM\RS_Service.exe" - 700
                  2876 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k imgsvc - 700
                  2920 | C:\Windows\System32\svchost.exe - SYSTEM - Normal - C:\Windows\System32\svchost.exe -k WerSvcGroup - 700
                  2928 | C:\Windows\system32\CNAB4RPK.EXE - SYSTEM - Normal - C:\Windows\system32\CNAB4RPK.EXE - 1788
                  2996 | C:\Windows\system32\SearchIndexer.exe - SYSTEM - Normal - C:\Windows\system32\SearchIndexer.exe /Embedding - 700
                  3108 | C:\Windows\system32\DRIVERS\xaudio.exe - SYSTEM - Normal - C:\Windows\system32\DRIVERS\xaudio.exe - 700
                  3172 | C:\Windows\system32\nipalsm.exe - SYSTEM - Normal - C:\Windows\system32\nipalsm.exe - 700
                  3496 | C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe - user - Normal - "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe" - 2460
                  3572 | C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe - user - Normal - "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe" - 2460
                  3584 | C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe - user - Normal - "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" - 2460
                  3592 | C:\Program Files\Fingerprint Sensor\ATSwpNav.exe - user - Normal - "C:\Program Files\Fingerprint Sensor\ATSwpNav.exe" -run - 2460
                  3612 | C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe - user - Normal - "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show - 2460
                  3876 | C:\Windows\system32\wbem\wmiprvse.exe - SYSTEM - Normal - C:\Windows\system32\wbem\wmiprvse.exe - 920
                  2132 | C:\Windows\system32\igfxsrvc.exe - user - Normal - C:\Windows\system32\igfxsrvc.exe -Embedding - 920
                  2812 | C:\Program Files\Launch Manager\LManager.exe - user - Normal - "C:\Program Files\Launch Manager\LManager.exe" - 2460
                  3008 | C:\Program Files\Apoint2K\Apoint.exe - user - Normal - "C:\Program Files\Apoint2K\Apoint.exe" - 2460
                  3044 | C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe - user - Normal - "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup - 2460
                  3132 | C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe - user - Normal - "C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe" - 2460
                  3240 | C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe - user - Normal - "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" - 2460
                  3244 | C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe - user - Normal - "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" - 2460
                  3400 | C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe - user - Normal - "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" - 2460
                  3456 | C:\Program Files\Java\jre6\bin\jusched.exe - user - Normal - "C:\Program Files\Java\jre6\bin\jusched.exe" - 2460
                  3528 | C:\Program Files\Internet Haut Débit Mobile\AutoDect.exe - user - Normal - "C:\Program Files\Internet Haut Débit Mobile\AutoDect.exe" - 2460
                  2684 | C:\Program Files\Common Files\Real\Update_OB\realsched.exe - user - Normal - "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot - 2460
                  3556 | C:\Program Files\National Instruments\Shared\Update Service\BackgroundService.exe - user - Normal - "C:\Program Files\National Instruments\Shared\Update Service\BackgroundService.exe" - 2460
                  2272 | C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe - user - Normal - "C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe" - 2460
                  3652 | C:\Program Files\HSPA USB MODEM\ModemListener.exe - user - Normal - "C:\Program Files\HSPA USB MODEM\ModemListener.exe" start - 2460
                  1212 | C:\Windows\System32\igfxtray.exe - user - Normal - "C:\Windows\System32\igfxtray.exe" - 2460
                  572 | C:\Windows\System32\hkcmd.exe - user - Normal - "C:\Windows\System32\hkcmd.exe" - 2460
                  1700 | C:\Windows\System32\igfxpers.exe - user - Normal - "C:\Windows\System32\igfxpers.exe" - 2460
                  3316 | C:\Windows\ehome\ehtray.exe - user - Normal - "C:\Windows\ehome\ehtray.exe" - 2460
                  3872 | C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe - user - Normal - "C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe" - 2460
                  1308 | C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE - user - Normal - "C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE" -m - 2460
                  3928 | C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe - user - Normal - "C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe" - 2460
                  3844 | C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe - user - Normal - "C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe" - 2460
                  4084 | C:\Program Files\Windows Media Player\wmpnscfg.exe - user - Normal - "C:\Program Files\Windows Media Player\wmpnscfg.exe" - 2460
                  2236 | C:\Windows\system32\wbem\wmiprvse.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\wbem\wmiprvse.exe - 920
                  4672 | C:\Program Files\Acer\Acer VCM\AcerVCM.exe - user - Normal - "C:\Program Files\Acer\Acer VCM\AcerVCM.exe" - 2460
                  4696 | C:\Program Files\Billeo\billeo.exe - user - Normal - "C:\Program Files\Billeo\billeo.exe" /signin - 2460
                  4704 | C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe - user - Normal - "C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe" - 2460
                  4712 | C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe - user - Normal - "C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe" - 2460
                  4728 | C:\Program Files\Convesoft\Orion\Messenger.exe - user - Normal - "C:\Program Files\Convesoft\Orion\Messenger.exe" - 2460
                  4868 | C:\Program Files\Windows Media Player\wmpnetwk.exe - SERVICE RÉSEAU - Normal - "C:\Program Files\Windows Media Player\wmpnetwk.exe" - 700
                  5100 | C:\Windows\ehome\ehmsas.exe - user - Normal - C:\Windows\ehome\ehmsas.exe -Embedding - 920
                  5108 | C:\Windows\system32\igfxext.exe - user - Normal - C:\Windows\system32\igfxext.exe -Embedding - 920
                  5168 | C:\Windows\system32\wbem\unsecapp.exe - user - Normal - C:\Windows\system32\wbem\unsecapp.exe -Embedding - 920
                  5232 | C:\Windows\system32\igfxsrvc.exe - user - Normal - C:\Windows\system32\igfxsrvc.exe -Embedding - 920
                  5456 | C:\Program Files\Apoint2K\ApMsgFwd.exe - user - Below Normal - "C:\Program Files\Apoint2K\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113} - 3008
                  5676 | C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe - user - Normal - "C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe" - 3612
                  5804 | C:\Program Files\Apoint2K\Apntex.exe - user - Normal - "Apntex.exe" - 5720
                  4360 | C:\Program Files\Acer\Acer VCM\acp2HID.exe - user - Normal - "C:\Program Files\Acer\Acer VCM\acp2HID.exe" - 4672
                  4476 | C:\Windows\system32\mdm.exe - user - Normal - C:\Windows\system32\mdm.exe -Embedding - 920
                  4416 | C:\Windows\system32\conime.exe - user - Normal - C:\Windows\system32\conime.exe - 5524
                  5924 | C:\Windows\system32\wuauclt.exe - user - Normal - "C:\Windows\system32\wuauclt.exe" - 1160
                  4216 | C:\Program Files8\wamp server\wampmanager.exe - user - Normal - "C:\Program Files8\wamp server\wampmanager.exe" - 2460
                  476 | c:\Program Files8\wamp server\bin\mysql\mysql5.5.8\bin\mysqld.exe - SYSTEM - Normal - "c:\Program Files8\wamp server\bin\mysql\mysql5.5.8\bin\mysqld.exe" wampmysqld - 700
                  6772 | c:\Program Files8\wamp server\bin\apache\apache2.2.17\bin\httpd.exe - SYSTEM - Normal - "c:\Program Files8\wamp server\bin\apache\apache2.2.17\bin\httpd.exe" -k runservice - 700
                  6256 | C:\Program Files8\wamp server\bin\apache\apache2.2.17\bin\httpd.exe - SYSTEM - Normal - "C:\Program Files8\wamp server\bin\apache\apache2.2.17\bin\httpd.exe" -d "C:/Program Files8/wamp server/bin/apache/Apache2.2.17" - 6772
                  2496 | C:\Windows\system32\SearchProtocolHost.exe - SYSTEM - Idle - "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe30_ Global\UsGthrCtrlFltPipeMssGthrPipe30 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" - 2996
                  7352 | C:\Windows\system32\SearchFilterHost.exe - SYSTEM - Idle - "C:\Windows\system32\SearchFilterHost.exe" 0 620 624 632 65536 628 - 2996
                  6284 | C:\Users\user\Desktop\Pre_scan.exe - user - High - "C:\Users\user\Desktop\Pre_scan.exe" - 2460
                  6536 | C:\Windows\System32\rundll32.exe - user - Normal - C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {3eef301f-b596-4c0b-bd92-013beafce793} -Embedding - 920
                  3860 | C:\Windows\system32\cmd.exe - user - Normal - cmd /c ""C:\Kill'em\Pv.bat" " - 6284
                  7528 | C:\Kill'em\Pv.exe - user - Normal - C:\Kill'em\pv.exe -o"%i | %f - %u - %p - %l - %r" - 3860

                  ¤¤¤¤¤¤¤¤¤¤ Démarrage avant suppression ¤¤¤¤¤¤¤¤¤¤

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "ehTray.exe"=C:\Windows\ehome\ehTray.exe
                  "REVAService"=C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
                  "E09FXLRD_20767757"="C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE" -m
                  "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                  "Z810SysStart"=C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe
                  "Z810PNP"=C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe
                  "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
                  "Tok-Cirrhatus"="C:\Users\user\AppData\Local\smss.exe"

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  "RtHDVCpl"=RtHDVCpl.exe
                  "eDataSecurity Loader"=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
                  "eAudio"="C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
                  "BkupTray"="C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
                  "ATSwpNav"="C:\Program Files\Fingerprint Sensor\ATSwpNav.exe" -run
                  "ZPdtWzdVitaKey MC3000"="C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
                  "LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe
                  "Apoint"=C:\Program Files\Apoint2K\Apoint.exe
                  "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  "ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
                  "eRecoveryService"=
                  "ArcadeDeluxeAgent"="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
                  "CLMLServer"="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
                  "PlayMovie"="C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
                  "ProductReg"="C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
                  "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe"
                  "autodetect"=C:\Program Files\Internet Haut Débit Mobile\AutoDect.exe
                  "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  "Corel File Shell Monitor"=c:\Program Files\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe
                  "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  "NI Background Service"=C:\Program Files\National Instruments\Shared\Update Service\BackgroundService.exe
                  "niDevMon"=C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe
                  "ModemListener"=C:\Program Files\HSPA USB MODEM\ModemListener.exe start
                  "IgfxTray"=C:\Windows\system32\igfxtray.exe
                  "HotKeysCmds"=C:\Windows\system32\hkcmd.exe
                  "Persistence"=C:\Windows\system32\igfxpers.exe
                  "MRT"="C:\Windows\system32\MRT.exe" /R
                  "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
                  "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

                  ¤¤¤¤¤¤¤¤¤¤ Winlogon

                  [HKLM | Winlogon] | Shell : Explorer.exe
                  [HKLM | Winlogon] | AutoRestartShell : 1
                  [HKLM | Winlogon] | userinit : userinit.exe -> C:\Windows\system32\userinit.exe,
                  [HKLM | Winlogon] | PowerDownAfterShutdown : 0 -> 1
                  [HKLM | Winlogon] | System :

                  ¤¤¤¤¤¤¤¤¤¤ Associations

                  [.exe] : exefile
                  [exefile | command] : "%1" %*
                  [.com] : comfile
                  [comfile | command] : "%1" %*
                  [.reg] : regfile
                  [regfile | command] : regedit.exe "%1"
                  [.scr] : scrfile
                  [scrfile | command] : "%1" /S
                  [.bat] : batfile
                  [batfile | command] : "%1" %*
                  [.cmd] : cmdfile
                  [cmdfile | command] : "%1" %*
                  [.pif] : piffile
                  [piffile | command] : "%1" %*
                  [.url] : InternetShortcut
                  [InternetShortcut | command] : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l
                  [Application.Manifest | command] : rundll32.exe dfshim.dll,ShOpenVerbApplication %1
                  [Application.Reference | command] : rundll32.exe dfshim.dll,ShOpenVerbShortcut %1|%2
                  [Folder | command] : %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L -> C:\Windows\explorer.exe

                  ¤

                  [Firefox | Command] | @ : "C:\Program Files\mozilla firefox\firefox.exe"
                  [Firefox - Safemode | Command] | @ : "C:\Program Files\mozilla firefox\firefox.exe" -safe-mode
                  [IE | Command] | @ : "C:\Program Files\internet explorer\iexplore.exe"
                  [Applications | IE | Command] | @ : "C:\Program Files\Internet Explorer\iexplore.exe" %1
                  [Chrome | Command] | @ : "C:\Program Files\Google\Chrome\Application\chrome.exe"
                  [Assoc | Applications] | @ : http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s -> http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s

                  ¤¤¤¤¤¤¤¤¤¤ Divers

                  [HKCU | HideDesktopIcons\NewStartPanel] | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0
                  [HKCU | HideDesktopIcons\NewStartPanel] | {F02C1A0D-BE21-4350-88B0-7367FC96EF3C} : 0
                  [HKLM | HideDesktopIcons\ClassicStartMenu] | {9343812e-1c37-4a49-a12e-4b2d810d956b} : 1 -> 0
                  [HKLM | HideDesktopIcons\ClassicStartMenu] | {4336a54d-038b-4685-ab02-99bb52d3fb8b} : 1 -> 0
                  [HKLM | HideDesktopIcons\NewStartPanel] | {F02C1A0D-BE21-4350-88B0-7367FC96EF3C} : 1 -> 0
                  [HKLM | HideDesktopIcons\NewStartPanel] | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 0
                  [HKLM | HideDesktopIcons\NewStartPanel] | {208D2C60-3AEA-1069-A2D7-08002B30309D} : 1 -> 0
                  [HKLM | HideDesktopIcons\NewStartPanel] | {871C5380-42A0-1069-A2EA-08002B30309D} : 1 -> 0
                  [HKLM | HideDesktopIcons\NewStartPanel] | {5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0} : 1 -> 0
                  [HKLM | HideDesktopIcons\NewStartPanel] | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0
                  [HKLM | HideDesktopIcons\NewStartPanel] | {9343812e-1c37-4a49-a12e-4b2d810d956b} : 1 -> 0
                  [HKLM | HideDesktopIcons\NewStartPanel] | {4336a54d-038b-4685-ab02-99bb52d3fb8b} : 1 -> 0
                  [HKCU | Desktop] | Wallpaper : C:\Users\Public\Pictures\Sample Pictures\Dock.jpg
                  Supprimé : [HKLM | policies\system] | DisableTaskMgr -> 0
                  Supprimé : [HKLM | policies\system] | DisableRegistryTools -> 0

                  ¤¤¤¤¤¤¤¤¤¤ Services

                  [Ndisuio] | Start : 3 : Actif
                  [Profsvc] | Start : 2 : Actif
                  [PlugPlay] | Start : 2 : Actif
                  [PEAUTH] | Start : 2 : Actif
                  [Parvdm] | Start : 2 : Inactif
                  [nsi] | Start : 2 : Actif
                  [NLASvc] | Start : 2 : Actif
                  [MPSsvc] | Start : 2 : Actif
                  [MMCSS] | Start : 2 : Actif
                  [luafv] | Start : 2 : Actif
                  [lltdio] | Start : 2 : Actif
                  [Iphlpsvc] | Start : 2 : Actif
                  [IKEEXT] | Start : 2 : Actif
                  [gpsvc] | Start : 2 : Actif
                  [lmhosts] | Start : 2 : Actif
                  [LanmanWorkstation] | Start : 2 : Actif
                  [LanmanServer] | Start : 2 : Actif
                  [agp440] | Start : 3 -> 2 : Inactif
                  [AudioEndpointBuilder] | Start : 2 : Actif
                  [Audiosrv] | Start : 2 : Actif
                  [BFE] | Start : 2 : Actif
                  [Bits] | Start : 2 : Actif
                  [CryptSvc] | Start : 2 : Actif
                  [EapHost] | Start : 3 -> 2 : Actif
                  [Wlansvc] | Start : 2 : Actif
                  [SharedAccess] | Start : 4 -> 2 : Inactif
                  [wuauserv] | Start : 2 : Actif
                  [WerSvc] | Start : 2 : Actif
                  [wscsvc] | Start : 2 : Actif

                  ¤¤¤¤¤¤¤¤¤¤ Internet Explorer

                  [HKCU | Main] | Start Page : https://www.google.co.ma/?gws_rd=ssl -> https://www.google.com/?gws_rd=ssl
                  [HKCU | Main] | Local Page : C:\Windows\system32\blank.htm
                  [HKCU | Main] | Search Page : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  [HKCU | Search] | SearchAssistant : -> https://www.google.com/?gws_rd=ssl

                  [HKLM | Main] | Start Page : https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fhomepage.acer.com%2frdr.aspx%3fb%3dACAW&l=040c&s=2&o=vp32&d=0209&m=aspire_2930 -> https://www.msn.com/fr-fr/?ocid=iehp
                  [HKLM | Main] | Local Page : C:\Windows\System32\blank.htm
                  [HKLM | Main] | Default_Search_URL : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  [HKLM | Main] | Default_Page_URL : http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0209&m=aspire_2930 -> https://www.msn.com/fr-fr/?ocid=iehp
                  [HKLM | Main] | Search Page : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                  ¤

                  [HKCU | PhishingFilter] | Enabled : -> 2
                  [HKCU | PhishingFilter] | EnabledV8 : 1
                  [HKCU | Internet Settings] | MigrateProxy : 1
                  [HKCU | Internet Settings] | WarnonBadCertRecving : 1
                  [HKCU | Internet Settings] | WarnOnHTTPSToHTTPRedirect : -> 1
                  [HKCU | Internet Settings] | WarnonZoneCrossing : 0 -> 1
                  [HKCU | Internet Settings] | AutoConfigProxy : wininet.dll

                  ¤¤¤¤¤¤¤¤¤¤ DNS

                  [HKLM | Tcpip\Parameters] | DhcpNameServer = 192.168.1.1
                  [HKLM\CCS | Interfaces\{13D0B8B7-5D0A-4140-9055-2AD08546121B}] | DhcpNameServer -> 10.1.100.1 10.1.100.2
                  [HKLM\CCS | Interfaces\{88224ADE-4B1D-4BB1-AE6C-FEF7AC6E5095}] | DhcpNameServer -> 192.168.1.1
                  [HKLM\CS1 | Interfaces\{13D0B8B7-5D0A-4140-9055-2AD08546121B}] | DhcpNameServer -> 10.1.100.1 10.1.100.2
                  [HKLM\CS1 | Interfaces\{88224ADE-4B1D-4BB1-AE6C-FEF7AC6E5095}] | DhcpNameServer -> 192.168.1.1
                  [HKLM\CS2 | Interfaces\{13D0B8B7-5D0A-4140-9055-2AD08546121B}] | DhcpNameServer -> 10.1.100.1 10.1.100.2
                  [HKLM\CS2 | Interfaces\{88224ADE-4B1D-4BB1-AE6C-FEF7AC6E5095}] | DhcpNameServer -> 192.168.1.1
                  [HKLM | Tcpip\Parameters] | NameServer =

                  ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

                  ::1 localhost
                  127.0.0.1 localhost

                  ¤¤¤¤¤¤¤¤¤¤ Processus

                  C:\Users\user\AppData\Local\Temp\RtkBtMnt.exe -> Processus stoppé
                  C:\Windows\explorer.exe -> Processus stoppé
                  C:\Windows\RtHDVCpl.exe -> Processus stoppé

                  ¤¤¤¤¤¤¤¤¤¤ Traitement Fichiers | Dossiers | Registre

                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$IBPOQNY.lnk
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$R0ZQ27O
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$R3CRH0Q
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RBPOQNY.lnk
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RJP5PEO
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$ROTOW3K
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RPC5DNP
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RPP1L2S
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RQ5BYIC
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RV7L6F4
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RWCZF6L
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\desktop.ini
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1001\desktop.ini
                  Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-500\desktop.ini
                  0
                  1. voilà:
                    http://www.cijoint.fr/cjlink.php?file=cj201106/cijDsPI9BV.txt

                    et merci encore pour l'aide :)
                    0
                    1. ressaie de le passer en mode sans echec stp
                      0
                      1. si mais je pense qu'il y a un truc qui 'empeche de fonctionner en mode normal , un truc costaud
                        0
                        1. donc je dois faire quoi?? relancer Pre_scan en mode sans echec ??
                          0
                          1. J'ai essayé de démarrer mon ordi en mode sans echec, mais ça n'a rien donné juste un ecran noir, j'ai bcp attendu apres j'ai redémarrer mon ordi en mode normal et c le mm prob aussi que l'ecran noir..Heeeeeeelp svp
                            0
                            1. ok redemarre avec "derniere bonne configuration connue
                              0
                              • 1
                              • 2
                              • 3
                              • 4
                              • 5
                              • 6