RogueKiller !!! Installation échec.

Bonjour,

Impossible d'installer RogueKiller

Voici le message d'erreur:

IpersistFile:::Save a échoué code: ox80070002.
Le fichier est introuvable

Donc ?

3 réponses

  1. Voici le rapport RogueKiller:

    RogueKiller Anti-Malware V13.0.12.0 (x64) [Nov 21 2018] (Gratuit) par Adlice Software
    email : https://www.adlice.com/contact/
    Site web : https://www.adlice.com/roguekiller/
    Système d'exploitation : Windows 10 (10.0.17763) 64 bits
    Démarré en : Mode normal
    Utilisateur : Franck_PC [Administrateur]
    Démarré depuis : C:\Program Files\RogueKiller\RogueKiller64.exe
    Mode : Scan Standard, Scan -- Date : 2018/11/22 17:28:42 (Durée : 00:21:47)

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processus ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    [PUP.HackTool (Potentiellement Malicieux)] Service_KMS.exe (3880) -- C:\Program Files\KMSpico\Service_KMS.exe -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] ace_update.exe (5180) -- (Innovative Digital Technologies) C:\Users\Franck_PC\AppData\Roaming\ACEStream\updater\ace_update.exe -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] ace_engine.exe (30232) -- (INNOVATIVE DIGITAL TECHNOLOGIES LLC) C:\Users\Franck_PC\AppData\Roaming\ACEStream\engine\ace_engine.exe -> Trouvé(e)

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Modules de Processus ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    [PUP.HackTool (Potentiellement Malicieux)] Service KMSELDI (3880) -- C:\Program Files\KMSpico\Service_KMS.exe -> Trouvé(e)

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tâches ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    [PUP.HackTool (Potentiellement Malicieux)] \AutoPico Daily Restart -- "C:\Program Files\KMSpico\AutoPico.exe" [/silent] -> Trouvé(e)

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registre ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    >>>>>> XX - Software
    [PUP.Reimage|PUP.Gen1 (Potentiellement Malicieux)] (X64) HKEY_LOCAL_MACHINE\Software\Reimage -- N/A -> Trouvé(e)
    [PUP.RegCurePro|PUP.Gen1 (Potentiellement Malicieux)] (X86) HKEY_LOCAL_MACHINE\Software\ParetoLogic -- N/A -> Trouvé(e)
    [PUP.RegCurePro|PUP.Gen1 (Potentiellement Malicieux)] (X64) HKEY_USERS\S-1-5-21-547520731-1142709591-4206038125-1001\Software\ParetoLogic -- N/A -> Trouvé(e)
    [PUP.RegCurePro|PUP.Gen1 (Potentiellement Malicieux)] (X86) HKEY_USERS\S-1-5-21-547520731-1142709591-4206038125-1001\Software\ParetoLogic -- N/A -> Trouvé(e)
    >>>>>> O4 - Run
    [PUP.Gen1 (Potentiellement Malicieux)] (X64) HKEY_USERS\S-1-5-21-547520731-1142709591-4206038125-1001\Software\Microsoft\Windows\CurrentVersion\Run|AceStream -- (INNOVATIVE DIGITAL TECHNOLOGIES LLC) C:\Users\Franck_PC\AppData\Roaming\ACEStream\engine\ace_engine.exe -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] (X86) HKEY_USERS\S-1-5-21-547520731-1142709591-4206038125-1001\Software\Microsoft\Windows\CurrentVersion\Run|AceStream -- (INNOVATIVE DIGITAL TECHNOLOGIES LLC) C:\Users\Franck_PC\AppData\Roaming\ACEStream\engine\ace_engine.exe -> Trouvé(e)
    >>>>>> O23 - Services
    [PUP.HackTool (Potentiellement Malicieux)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Service KMSELDI -- "C:\Program Files\KMSpico\Service_KMS.exe" -> Trouvé(e)
    >>>>>> O87 - Firewall
    [Suspicious.Path (Potentiellement Malicieux)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{631C3CC8-1D8A-4E8B-8ABF-F8F70DD41BBA}C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|Profile=Public|App=C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe|Name=spotty.exe|Desc=spotty.exe|Defer=User| (C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe) -> Trouvé(e)
    [Suspicious.Path (Potentiellement Malicieux)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{C36590E1-C2D3-4EE9-9C3A-1B8B72921010}C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe|Name=spotty.exe|Desc=spotty.exe|Defer=User| (C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe) -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{8C570846-592E-42CB-9AF2-6A5C4011FC71}C:\users\franck_pc\appdata\roaming\acestream\engine\ace_engine.exe -- (INNOVATIVE DIGITAL TECHNOLOGIES LLC) v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\franck_pc\appdata\roaming\acestream\engine\ace_engine.exe|Name=ace_engine.exe|Desc=ace_engine.exe|Defer=User| (C:\users\franck_pc\appdata\roaming\acestream\engine\ace_engine.exe) -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{A44C8C96-CC1A-4DE9-BCBE-1C9F6553424E}C:\users\franck_pc\appdata\roaming\acestream\engine\ace_engine.exe -- (INNOVATIVE DIGITAL TECHNOLOGIES LLC) v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\franck_pc\appdata\roaming\acestream\engine\ace_engine.exe|Name=ace_engine.exe|Desc=ace_engine.exe|Defer=User| (C:\users\franck_pc\appdata\roaming\acestream\engine\ace_engine.exe) -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{CCE8068E-BE96-4F2D-8552-0C36AC6C52BA} -- (INNOVATIVE DIGITAL TECHNOLOGIES LLC) v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Users\Franck_PC\AppData\Roaming\ACEStream\engine\ace_engine.exe|Name=AceStream| (C:\Users\Franck_PC\AppData\Roaming\ACEStream\engine\ace_engine.exe) -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{8FA608B7-2C1B-49A6-9542-D5C1811E558E} -- (INNOVATIVE DIGITAL TECHNOLOGIES LLC) v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Users\Franck_PC\AppData\Roaming\ACEStream\engine\ace_engine.exe|Name=AceStream| (C:\Users\Franck_PC\AppData\Roaming\ACEStream\engine\ace_engine.exe) -> Trouvé(e)
    [Suspicious.Path (Potentiellement Malicieux)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{642A2CD4-CF8E-4270-B96D-7A02F9603764}C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe|Name=spotty.exe|Desc=spotty.exe|Defer=User| (C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe) -> Trouvé(e)
    [Suspicious.Path (Potentiellement Malicieux)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{2AF76B93-233E-4512-A169-C3492C753731}C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|Profile=Public|App=C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe|Name=spotty.exe|Desc=spotty.exe|Defer=User| (C:\users\franck_pc\appdata\roaming\kodi\addons\plugin.audio.spotify\resources\lib\spotty\windows\spotty.exe) -> Trouvé(e)

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Fichier Hosts ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    [Hj.Hosts (Malicieux)] pagead2.googlesyndication.com => 0.0.0.0 -> Trouvé(e)
    [Hj.Hosts (Malicieux)] pagead2.googlesyndication.com => 0.0.0.0 -> Trouvé(e)
    [Hj.Hosts (Malicieux)] pagead2.googlesyndication.com => 0.0.0.0 -> Trouvé(e)

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Fichiers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    [PUP.HackTool (Potentiellement Malicieux)] (file) SECOH-QAD.exe -- C:\Windows\SECOH-QAD.exe -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] (folder) ACEStream -- C:\Users\Franck_PC\AppData\Roaming\ACEStream -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] (folder) AdvertismentImages -- C:\Users\Franck_PC\AppData\Roaming\AdvertismentImages -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] (folder) Ace Stream Media -- C:\Users\Franck_PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media -> Trouvé(e)
    [PUP.Gen3 (Potentiellement Malicieux)] (file) securesearch.xml -- C:\Users\Franck_PC\AppData\Roaming\Mozilla\Firefox\Profiles\d9kaamab.default\searchplugins\securesearch.xml -> Trouvé(e)
    [PUP.DriverToolkit (Potentiellement Malicieux)] (folder) DriverToolkit -- C:\Users\Franck_PC\AppData\Local\DriverToolkit -> Trouvé(e)
    [PUP.HackTool (Potentiellement Malicieux)] (folder) KMSpico -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico -> Trouvé(e)
    [PUP.HackTool (Potentiellement Malicieux)] (folder) KMSpico -- C:\Program Files\KMSpico -> Trouvé(e)
    [PUP.Popcorn|PUP.Gen1 (Potentiellement Malicieux)] (folder) Popcorn Time -- C:\Program Files (x86)\Popcorn Time -> Trouvé(e)
    [PUP.HackTool (Potentiellement Malicieux)] (folder) KMSpico -- C:\Program Files\KMSpico -> Trouvé(e)
    [PUP.Popcorn|PUP.Gen1 (Potentiellement Malicieux)] (folder) Popcorn Time -- C:\Program Files (x86)\Popcorn Time -> Trouvé(e)
    [PUP.DriverToolkit (Potentiellement Malicieux)] (folder) DriverToolkit -- C:\Users\Franck_PC\AppData\Local\DriverToolkit -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] (folder) ACEStream -- C:\Users\Franck_PC\AppData\Roaming\ACEStream -> Trouvé(e)
    [PUP.Gen1 (Potentiellement Malicieux)] (folder) AdvertismentImages -- C:\Users\Franck_PC\AppData\Roaming\AdvertismentImages -> Trouvé(e)

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Navigateurs web ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    Maintenant je fais quoi ?
    0
    1. Modérateur
      Désinstalle DriverToolkit
      Supprime RogueKiller.
      Utilise Malwarebytes.
      0
  2. Modérateur
    Désinstalle DriverToolkit
    Supprime RogueKiller.
    Utilise Malwarebytes.

    Pour vérifier ton ordinateur, pour d'éventuels infections et avoir un état général du système :

    Suis tutoriel FRST en cliquant sur ce lien bleu. ( prends le temps de lire attentivement - tout y est bien expliqué ).

    Télécharge et lance le scan FRST,
    Attendre la fin du scan, un message indique que l'analyse est terminée.

    Trois rapports FRST seront générés :
    • FRST.txt
    • Shortcut.
    • Additionnal.txt


    Envoie ces 3 rapports sur le site https://pjjoint.malekal.com/ et en retour donne les 3 liens pjjoint qui mènent aux rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.

    0