Comprendre le rapport RogueKiller

Après avoir télécharger RogueKiller depuis le site: https://www.luanagames.com/index.fr.html
et suivre les étapes qu'il faut, voilà le rapport:

RogueKiller V5.2.2 [05/06/2011] par Tigzy
contact sur https://www.luanagames.com/index.fr.html
mail: tigzyRK<at>gmail<dot>com
Remontees: https://www.luanagames.com/index.fr.html

Systeme d'exploitation: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Demarrage : Mode normal
Utilisateur: user [Droits d'admin]
Mode: Suppression -- Date : 15/06/2011 12:58:01

Processus malicieux: 3
[SUSP PATH] PLFSetI.exe -- c:\windows\plfseti.exe -> KILLED
[SUSP PATH] lsnfier.exe -- c:\users\user\appdata\roaming\microsoft\notification de cadeaux msn\lsnfier.exe -> KILLED
[SUSP PATH] jvu.exe -- c:\users\user\appdata\local\jvu.exe -> KILLED

Entrees de registre: 12
[SUSP PATH] HKCU\[...]\Run : biecei (C:\Users\user\biecei.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : PLFSetI (C:\Windows\PLFSetI.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : RestartNeroSetup ("C:\Users\user\AppData\Local\Temp\NERO13823\setupx.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : adiras (C:\Windows\adiras.exe) -> DELETED
[SUSP PATH] Notification de cadeaux MSN.lnk : C:\Users\user\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe -> DELETED
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[FILE ASSO] HKCU\[...]Software\Classes\.exe\shell\open\command : ("C:\Users\user\AppData\Local\jvu.exe" -a "%1" %*) -> REPLACED : ("%1" %*)
[FILE ASSO] HKCU\[...]Software\Classes\exefile\shell\open\command : ("C:\Users\user\AppData\Local\jvu.exe" -a "%1" %*) -> REPLACED : ("%1" %*)
[FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command : ("C:\Users\user\AppData\Local\jvu.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") -> REPLACED : ("C:\Program Files\mozilla firefox\firefox.exe")
[FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command : ("C:\Users\user\AppData\Local\jvu.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) -> REPLACED : ("C:\Program Files\mozilla firefox\firefox.exe" -safe-mode)
[FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command : ("C:\Users\user\AppData\Local\jvu.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") -> REPLACED : ("C:\Program Files\internet explorer\iexplore.exe")

Fichier HOSTS:
127.0.0.1 localhost
::1 localhost
127.0.0.1 localhost

Termine : << RKreport[1].txt >>
RKreport[1].txt

109 réponses

Résumé de la discussion

L'objet analyse un rapport RogueKiller sur Windows Vista 32 bits, détaillant des processus malicieux et des entrées de registre modifiées ainsi que des modifications de liaisons et d'associations de fichiers. Plusieurs réponses proposent des solutions, notamment une restauration système et des procédures techniques utilisant CFScript/ComboFix pour nettoyer les éléments détectés après l'analyse et stabiliser l'ordinateur. D'autres échanges évoquent des vérifications comme VirusTotal et des analyses avec OTL, ou des scripts pré-script pour détecter des éléments persistants, tout en évoquant des risques liés à l'emploi d'outils non officiels. Des mentions soulignent aussi que des solutions suggérées touchent des systèmes piratés et des questions de réparation, apportant une dimension de sécurité et de prudence.

Bobot (l’IA à votre service)
  1. salut as-tu des fichiers / dossiers cachés dans ton menu demarrer ou dans tes documents?
    1. en tout cas voilà le rapport:

      RogueKiller V5.2.2 [05/06/2011] par Tigzy
      contact sur https://www.luanagames.com/index.fr.html
      mail: tigzyRK<at>gmail<dot>com
      Remontees: https://www.luanagames.com/index.fr.html

      Systeme d'exploitation: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
      Demarrage : Mode normal
      Utilisateur: user [Droits d'admin]
      Mode: Raccourcis RAZ -- Date : 15/06/2011 16:12:32

      Processus malicieux: 4
      [SUSP PATH] winlogon.exe -- c:\users\user\appdata\local\winlogon.exe -> KILLED
      [SUSP PATH] services.exe -- c:\users\user\appdata\local\services.exe -> KILLED
      [SUSP PATH] lsass.exe -- c:\users\user\appdata\local\lsass.exe -> KILLED
      [SUSP PATH] inetinfo.exe -- c:\users\user\appdata\local\inetinfo.exe -> KILLED

      Attributs de fichiers restaures:
      Bureau: Success 2 / Fail 0
      Lancement rapide: Success 0 / Fail 0
      Programmes: Success 272 / Fail 0
      Menu demarrer: Success 3 / Fail 0
      Dossier utilisateur: Success 429 / Fail 0
      Mes documents: Success 10 / Fail 0
      Mes favoris: Success 0 / Fail 0
      Mes images: Success 0 / Fail 0
      Ma musique: Success 8 / Fail 0
      Mes videos: Success 0 / Fail 0
      Disques locaux: Success 494 / Fail 0
      Sauvegarde: [NOT FOUND]

      Lecteurs:
      [C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
      [D:] \Device\HarddiskVolume3 -- 0x3 --> Restored
      [E:] \Device\CdRom0 -- 0x5 --> Skipped

      Termine : << RKreport[2].txt >>
      RKreport[1].txt ; RKreport[2].txt
      1. desactive ton antivirus
        desactive Windows defender si présent
        desactive ton pare-feu

        Ferme toutes tes appilications en cours

        telecharge et enregistre ceci sur ton bureau :

        Pre_Scan

        s'il n'est pas sur ton bureau coupe-le de ton dossier telechargements et colle-le sur ton bureau

        Avertissement: Il y aura une extinction courte du bureau --> pas de panique.

        une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan.txt" sur le bureau.

        si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

        si l'outil semble ne pas avoir fonctionné renomme-le winlogon , ou change son extension en .com ou .scr

        Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

        Poste Pre_Scan.txt qui apparaitra sur le bureau en fin de scan

        ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

        clique sur ce lien : http://www.cijoint.fr/

        ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

        ▶ Clique sur Ouvrir.

        ▶ Clique sur "Cliquez ici pour déposer le fichier".

        Un lien de cette forme :

        http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

        est ajouté dans la page.

        ▶ Copie ce lien dans ta réponse.
        1. J'ai lancé Pre_scan, Il y a eu une extinction courte du bureau, les fenêtres noires qui clignotent aussi
          mais après mon ordi a signalé une erreur (une page bleue) et il a redémarré
          après quand quand il a redémarré il y a eu une petite notification qui dit que les programmes malveillants ont été partiellement supprimés et il me demande si je veux terminer la suppression.
          alors quoi faire mnt ??
          1. Pre_scan.txt n'a pas été créer sur le bureau, c normal puisqu'il y a eu un interruption
            1. Exactement, le fichier Pre_scan existe dans C:\ =)
              le voilà:

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan 1.0.2.13 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

              ¤¤¤¤¤ XP | Vista | Seven - 32/64 bits ¤¤¤¤¤

              Mis à jour le 15/06/2011 | 12.30 par g3n-h@ckm@n
              Utilisateur : user (Administrateurs)
              Ordinateur : LAMIAE

              Système d'exploitation : Windows Vista (TM) Home Premium (32 bits) HomePremium Service Pack 1
              Enregistré sous : user
              Processeur : Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
              Identification : x86 Family 6 Model 23 Stepping 10
              Internet Explorer : 8.0.6001.19048
              Mozilla Firefox : 4.0.1 (fr)
              Pare-feu windows : Actif
              Windows Defender : Inactif

              Scan : 16:31:21 | 15/06/2011

              ¤¤¤¤¤¤¤¤¤¤ Sessions

              [HKLM | ProfileList] | S-1-5-21-3616354201-1143711275-3927985168-1000 : ProfileImagePath -> C:\Users\user
              [HKLM | ProfileList] | S-1-5-21-3616354201-1143711275-3927985168-1000 : RefCount -> 6
              [HKLM | ProfileList] | S-1-5-21-3616354201-1143711275-3927985168-1000 : State -> 0

              ¤¤¤¤¤¤¤¤¤¤ Verification des Fichiers

              C:\Windows\System32\compcln.exe........absent !!!!
              C:\Windows\System32\compcln.exe........Impossible de télécharger le fichier , non replacé !!!!

              C:\Windows\System32\DevicePairingWizard.exe........absent !!!!
              C:\Windows\System32\DevicePairingWizard.exe........Impossible de télécharger le fichier , non replacé !!!!

              C:\Windows\System32\IasMigReader.exe........absent !!!!
              C:\Windows\System32\IasMigReader.exe........Impossible de télécharger le fichier , non replacé !!!!

              C:\Windows\System32\spinstall.exe........absent !!!!
              C:\Windows\System32\spinstall.exe........Impossible de télécharger le fichier , non replacé !!!!

              C:\Windows\System32\spreview.exe........absent !!!!
              C:\Windows\System32\spreview.exe........Impossible de télécharger le fichier , non replacé !!!!

              ¤¤¤¤¤¤¤¤¤¤¤ Processus en cours

              Demarrage : Normal

              460 | C:\Windows\System32\smss.exe - SYSTEM - Normal - \SystemRoot\System32\smss.exe - 4
              604 | C:\Windows\system32\csrss.exe - SYSTEM - Normal - C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 - 592
              648 | C:\Windows\system32\wininit.exe - SYSTEM - High - wininit.exe - 592
              660 | C:\Windows\system32\csrss.exe - SYSTEM - Normal - C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 - 640
              700 | C:\Windows\system32\services.exe - SYSTEM - Normal - C:\Windows\system32\services.exe - 648
              712 | C:\Windows\system32\lsass.exe - SYSTEM - Normal - C:\Windows\system32\lsass.exe - 648
              724 | C:\Windows\system32\lsm.exe - SYSTEM - Normal - C:\Windows\system32\lsm.exe - 648
              808 | C:\Windows\system32\winlogon.exe - SYSTEM - High - winlogon.exe - 640
              920 | C:\Windows\system32\svchost.exe - SYSTEM - Normal - C:\Windows\system32\svchost.exe -k DcomLaunch - 700
              984 | C:\Windows\system32\svchost.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\svchost.exe -k rpcss - 700
              1052 | C:\Windows\System32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - 700
              1132 | C:\Windows\System32\svchost.exe - SYSTEM - Normal - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - 700
              1160 | C:\Windows\system32\svchost.exe - SYSTEM - Normal - C:\Windows\system32\svchost.exe -k netsvcs - 700
              1296 | C:\Windows\system32\svchost.exe - SYSTEM - Normal - C:\Windows\system32\svchost.exe -k GPSvcGroup - 700
              1324 | C:\Windows\system32\SLsvc.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\SLsvc.exe - 700
              1372 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k LocalService - 700
              1512 | C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe - SYSTEM - Normal - "C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe" - 1084
              1572 | C:\Windows\system32\svchost.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\svchost.exe -k NetworkService - 700
              1788 | C:\Windows\System32\spoolsv.exe - SYSTEM - Normal - C:\Windows\System32\spoolsv.exe - 700
              1820 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork - 700
              1988 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k bthsvcs - 700
              2024 | C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe - SYSTEM - Normal - "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe" - 700
              236 | C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe - SYSTEM - Normal - "C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe" - 700
              292 | C:\Program Files\Common Files\DeviceHelper\DeviceManager.exe - SYSTEM - Normal - "C:\Program Files\Common Files\DeviceHelper\DeviceManager.exe" -start - 700
              332 | C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe - SYSTEM - Normal - "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe" - 700
              968 | C:\Program Files\Acer\Empowering Technology\Service\ETService.exe - SYSTEM - Normal - "C:\Program Files\Acer\Empowering Technology\Service\ETService.exe" - 700
              1508 | C:\Program Files\Acer\Acer Bio Protection\BASVC.exe - SYSTEM - Normal - "C:\Program Files\Acer\Acer Bio Protection\BASVC.exe" - 700
              1668 | C:\Program Files\Common Files\LightScribe\LSSrvc.exe - SYSTEM - Normal - "C:\Program Files\Common Files\LightScribe\LSSrvc.exe" - 700
              2032 | C:\Windows\system32\lkads.exe - SYSTEM - Normal - C:\Windows\system32\lkads.exe - 700
              2016 | C:\Windows\system32\lktsrv.exe - SYSTEM - Normal - C:\Windows\system32\lktsrv.exe - 700
              384 | C:\Acer\Mobility Center\MobilityService.exe - SYSTEM - Normal - "C:\Acer\Mobility Center\MobilityService.exe" -p - 700
              284 | C:\Program Files\National Instruments\MAX\nimxs.exe - SYSTEM - Normal - "C:\Program Files\National Instruments\MAX\nimxs.exe" - 700
              2076 | C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe - SYSTEM - Normal - "C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe" - 700
              2224 | C:\Windows\system32\nipalsm.exe - SYSTEM - Normal - C:\Windows\system32\nipalsm.exe - 700
              2260 | C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe - SYSTEM - Normal - "C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe" - 700
              2300 | C:\Windows\system32\nisvcloc.exe - SYSTEM - Normal - C:\Windows\system32\nisvcloc.exe -s - 700
              2376 | C:\Windows\system32\taskeng.exe - SYSTEM - Below Normal - taskeng.exe {94EF75DC-A004-433A-9177-1546B3A4CB93} - 1160
              2416 | C:\Windows\system32\Dwm.exe - user - High - "C:\Windows\system32\Dwm.exe" - 1132
              2472 | C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe - SYSTEM - Normal - "C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe" - 700
              2508 | C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe - SYSTEM - Normal - "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe" - 700
              2564 | C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe - SYSTEM - Normal - "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe" - 700
              2616 | C:\Windows\system32\svchost.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted - 700
              2640 | c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe - SYSTEM - Normal - "c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" - 700
              2752 | C:\Program Files\Cyberlink\Shared files\RichVideo.exe - SYSTEM - Normal - "C:\Program Files\Cyberlink\Shared files\RichVideo.exe" - 700
              2796 | C:\Windows\system32\taskeng.exe - user - Normal - taskeng.exe {94F68C75-B3EF-472A-BAC4-2862994403D8} - 1160
              2820 | C:\Program Files\Acer\Acer VCM\RS_Service.exe - SYSTEM - Normal - "C:\Program Files\Acer\Acer VCM\RS_Service.exe" - 700
              2876 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k imgsvc - 700
              2920 | C:\Windows\System32\svchost.exe - SYSTEM - Normal - C:\Windows\System32\svchost.exe -k WerSvcGroup - 700
              2928 | C:\Windows\system32\CNAB4RPK.EXE - SYSTEM - Normal - C:\Windows\system32\CNAB4RPK.EXE - 1788
              2996 | C:\Windows\system32\SearchIndexer.exe - SYSTEM - Normal - C:\Windows\system32\SearchIndexer.exe /Embedding - 700
              3108 | C:\Windows\system32\DRIVERS\xaudio.exe - SYSTEM - Normal - C:\Windows\system32\DRIVERS\xaudio.exe - 700
              3172 | C:\Windows\system32\nipalsm.exe - SYSTEM - Normal - C:\Windows\system32\nipalsm.exe - 700
              3496 | C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe - user - Normal - "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe" - 2460
              3572 | C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe - user - Normal - "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe" - 2460
              3584 | C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe - user - Normal - "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" - 2460
              3592 | C:\Program Files\Fingerprint Sensor\ATSwpNav.exe - user - Normal - "C:\Program Files\Fingerprint Sensor\ATSwpNav.exe" -run - 2460
              3612 | C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe - user - Normal - "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show - 2460
              3876 | C:\Windows\system32\wbem\wmiprvse.exe - SYSTEM - Normal - C:\Windows\system32\wbem\wmiprvse.exe - 920
              2132 | C:\Windows\system32\igfxsrvc.exe - user - Normal - C:\Windows\system32\igfxsrvc.exe -Embedding - 920
              2812 | C:\Program Files\Launch Manager\LManager.exe - user - Normal - "C:\Program Files\Launch Manager\LManager.exe" - 2460
              3008 | C:\Program Files\Apoint2K\Apoint.exe - user - Normal - "C:\Program Files\Apoint2K\Apoint.exe" - 2460
              3044 | C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe - user - Normal - "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup - 2460
              3132 | C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe - user - Normal - "C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe" - 2460
              3240 | C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe - user - Normal - "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" - 2460
              3244 | C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe - user - Normal - "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" - 2460
              3400 | C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe - user - Normal - "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" - 2460
              3456 | C:\Program Files\Java\jre6\bin\jusched.exe - user - Normal - "C:\Program Files\Java\jre6\bin\jusched.exe" - 2460
              3528 | C:\Program Files\Internet Haut Débit Mobile\AutoDect.exe - user - Normal - "C:\Program Files\Internet Haut Débit Mobile\AutoDect.exe" - 2460
              2684 | C:\Program Files\Common Files\Real\Update_OB\realsched.exe - user - Normal - "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot - 2460
              3556 | C:\Program Files\National Instruments\Shared\Update Service\BackgroundService.exe - user - Normal - "C:\Program Files\National Instruments\Shared\Update Service\BackgroundService.exe" - 2460
              2272 | C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe - user - Normal - "C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe" - 2460
              3652 | C:\Program Files\HSPA USB MODEM\ModemListener.exe - user - Normal - "C:\Program Files\HSPA USB MODEM\ModemListener.exe" start - 2460
              1212 | C:\Windows\System32\igfxtray.exe - user - Normal - "C:\Windows\System32\igfxtray.exe" - 2460
              572 | C:\Windows\System32\hkcmd.exe - user - Normal - "C:\Windows\System32\hkcmd.exe" - 2460
              1700 | C:\Windows\System32\igfxpers.exe - user - Normal - "C:\Windows\System32\igfxpers.exe" - 2460
              3316 | C:\Windows\ehome\ehtray.exe - user - Normal - "C:\Windows\ehome\ehtray.exe" - 2460
              3872 | C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe - user - Normal - "C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe" - 2460
              1308 | C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE - user - Normal - "C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE" -m - 2460
              3928 | C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe - user - Normal - "C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe" - 2460
              3844 | C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe - user - Normal - "C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe" - 2460
              4084 | C:\Program Files\Windows Media Player\wmpnscfg.exe - user - Normal - "C:\Program Files\Windows Media Player\wmpnscfg.exe" - 2460
              2236 | C:\Windows\system32\wbem\wmiprvse.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\wbem\wmiprvse.exe - 920
              4672 | C:\Program Files\Acer\Acer VCM\AcerVCM.exe - user - Normal - "C:\Program Files\Acer\Acer VCM\AcerVCM.exe" - 2460
              4696 | C:\Program Files\Billeo\billeo.exe - user - Normal - "C:\Program Files\Billeo\billeo.exe" /signin - 2460
              4704 | C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe - user - Normal - "C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe" - 2460
              4712 | C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe - user - Normal - "C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe" - 2460
              4728 | C:\Program Files\Convesoft\Orion\Messenger.exe - user - Normal - "C:\Program Files\Convesoft\Orion\Messenger.exe" - 2460
              4868 | C:\Program Files\Windows Media Player\wmpnetwk.exe - SERVICE RÉSEAU - Normal - "C:\Program Files\Windows Media Player\wmpnetwk.exe" - 700
              5100 | C:\Windows\ehome\ehmsas.exe - user - Normal - C:\Windows\ehome\ehmsas.exe -Embedding - 920
              5108 | C:\Windows\system32\igfxext.exe - user - Normal - C:\Windows\system32\igfxext.exe -Embedding - 920
              5168 | C:\Windows\system32\wbem\unsecapp.exe - user - Normal - C:\Windows\system32\wbem\unsecapp.exe -Embedding - 920
              5232 | C:\Windows\system32\igfxsrvc.exe - user - Normal - C:\Windows\system32\igfxsrvc.exe -Embedding - 920
              5456 | C:\Program Files\Apoint2K\ApMsgFwd.exe - user - Below Normal - "C:\Program Files\Apoint2K\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113} - 3008
              5676 | C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe - user - Normal - "C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe" - 3612
              5804 | C:\Program Files\Apoint2K\Apntex.exe - user - Normal - "Apntex.exe" - 5720
              4360 | C:\Program Files\Acer\Acer VCM\acp2HID.exe - user - Normal - "C:\Program Files\Acer\Acer VCM\acp2HID.exe" - 4672
              4476 | C:\Windows\system32\mdm.exe - user - Normal - C:\Windows\system32\mdm.exe -Embedding - 920
              4416 | C:\Windows\system32\conime.exe - user - Normal - C:\Windows\system32\conime.exe - 5524
              5924 | C:\Windows\system32\wuauclt.exe - user - Normal - "C:\Windows\system32\wuauclt.exe" - 1160
              4216 | C:\Program Files8\wamp server\wampmanager.exe - user - Normal - "C:\Program Files8\wamp server\wampmanager.exe" - 2460
              476 | c:\Program Files8\wamp server\bin\mysql\mysql5.5.8\bin\mysqld.exe - SYSTEM - Normal - "c:\Program Files8\wamp server\bin\mysql\mysql5.5.8\bin\mysqld.exe" wampmysqld - 700
              6772 | c:\Program Files8\wamp server\bin\apache\apache2.2.17\bin\httpd.exe - SYSTEM - Normal - "c:\Program Files8\wamp server\bin\apache\apache2.2.17\bin\httpd.exe" -k runservice - 700
              6256 | C:\Program Files8\wamp server\bin\apache\apache2.2.17\bin\httpd.exe - SYSTEM - Normal - "C:\Program Files8\wamp server\bin\apache\apache2.2.17\bin\httpd.exe" -d "C:/Program Files8/wamp server/bin/apache/Apache2.2.17" - 6772
              2496 | C:\Windows\system32\SearchProtocolHost.exe - SYSTEM - Idle - "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe30_ Global\UsGthrCtrlFltPipeMssGthrPipe30 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" - 2996
              7352 | C:\Windows\system32\SearchFilterHost.exe - SYSTEM - Idle - "C:\Windows\system32\SearchFilterHost.exe" 0 620 624 632 65536 628 - 2996
              6284 | C:\Users\user\Desktop\Pre_scan.exe - user - High - "C:\Users\user\Desktop\Pre_scan.exe" - 2460
              6536 | C:\Windows\System32\rundll32.exe - user - Normal - C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {3eef301f-b596-4c0b-bd92-013beafce793} -Embedding - 920
              3860 | C:\Windows\system32\cmd.exe - user - Normal - cmd /c ""C:\Kill'em\Pv.bat" " - 6284
              7528 | C:\Kill'em\Pv.exe - user - Normal - C:\Kill'em\pv.exe -o"%i | %f - %u - %p - %l - %r" - 3860

              ¤¤¤¤¤¤¤¤¤¤ Démarrage avant suppression ¤¤¤¤¤¤¤¤¤¤

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "ehTray.exe"=C:\Windows\ehome\ehTray.exe
              "REVAService"=C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
              "E09FXLRD_20767757"="C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE" -m
              "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              "Z810SysStart"=C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe
              "Z810PNP"=C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe
              "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
              "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
              "Tok-Cirrhatus"="C:\Users\user\AppData\Local\smss.exe"

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
              "RtHDVCpl"=RtHDVCpl.exe
              "eDataSecurity Loader"=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
              "eAudio"="C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
              "BkupTray"="C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
              "ATSwpNav"="C:\Program Files\Fingerprint Sensor\ATSwpNav.exe" -run
              "ZPdtWzdVitaKey MC3000"="C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
              "LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe
              "Apoint"=C:\Program Files\Apoint2K\Apoint.exe
              "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
              "ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
              "eRecoveryService"=
              "ArcadeDeluxeAgent"="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
              "CLMLServer"="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
              "PlayMovie"="C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
              "ProductReg"="C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
              "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe"
              "autodetect"=C:\Program Files\Internet Haut Débit Mobile\AutoDect.exe
              "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
              "Corel File Shell Monitor"=c:\Program Files\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe
              "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
              "NI Background Service"=C:\Program Files\National Instruments\Shared\Update Service\BackgroundService.exe
              "niDevMon"=C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe
              "ModemListener"=C:\Program Files\HSPA USB MODEM\ModemListener.exe start
              "IgfxTray"=C:\Windows\system32\igfxtray.exe
              "HotKeysCmds"=C:\Windows\system32\hkcmd.exe
              "Persistence"=C:\Windows\system32\igfxpers.exe
              "MRT"="C:\Windows\system32\MRT.exe" /R
              "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
              "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

              ¤¤¤¤¤¤¤¤¤¤ Winlogon

              [HKLM | Winlogon] | Shell : Explorer.exe
              [HKLM | Winlogon] | AutoRestartShell : 1
              [HKLM | Winlogon] | userinit : userinit.exe -> C:\Windows\system32\userinit.exe,
              [HKLM | Winlogon] | PowerDownAfterShutdown : 0 -> 1
              [HKLM | Winlogon] | System :

              ¤¤¤¤¤¤¤¤¤¤ Associations

              [.exe] : exefile
              [exefile | command] : "%1" %*
              [.com] : comfile
              [comfile | command] : "%1" %*
              [.reg] : regfile
              [regfile | command] : regedit.exe "%1"
              [.scr] : scrfile
              [scrfile | command] : "%1" /S
              [.bat] : batfile
              [batfile | command] : "%1" %*
              [.cmd] : cmdfile
              [cmdfile | command] : "%1" %*
              [.pif] : piffile
              [piffile | command] : "%1" %*
              [.url] : InternetShortcut
              [InternetShortcut | command] : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l
              [Application.Manifest | command] : rundll32.exe dfshim.dll,ShOpenVerbApplication %1
              [Application.Reference | command] : rundll32.exe dfshim.dll,ShOpenVerbShortcut %1|%2
              [Folder | command] : %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L -> C:\Windows\explorer.exe

              ¤

              [Firefox | Command] | @ : "C:\Program Files\mozilla firefox\firefox.exe"
              [Firefox - Safemode | Command] | @ : "C:\Program Files\mozilla firefox\firefox.exe" -safe-mode
              [IE | Command] | @ : "C:\Program Files\internet explorer\iexplore.exe"
              [Applications | IE | Command] | @ : "C:\Program Files\Internet Explorer\iexplore.exe" %1
              [Chrome | Command] | @ : "C:\Program Files\Google\Chrome\Application\chrome.exe"
              [Assoc | Applications] | @ : http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s -> http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s

              ¤¤¤¤¤¤¤¤¤¤ Divers

              [HKCU | HideDesktopIcons\NewStartPanel] | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0
              [HKCU | HideDesktopIcons\NewStartPanel] | {F02C1A0D-BE21-4350-88B0-7367FC96EF3C} : 0
              [HKLM | HideDesktopIcons\ClassicStartMenu] | {9343812e-1c37-4a49-a12e-4b2d810d956b} : 1 -> 0
              [HKLM | HideDesktopIcons\ClassicStartMenu] | {4336a54d-038b-4685-ab02-99bb52d3fb8b} : 1 -> 0
              [HKLM | HideDesktopIcons\NewStartPanel] | {F02C1A0D-BE21-4350-88B0-7367FC96EF3C} : 1 -> 0
              [HKLM | HideDesktopIcons\NewStartPanel] | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 0
              [HKLM | HideDesktopIcons\NewStartPanel] | {208D2C60-3AEA-1069-A2D7-08002B30309D} : 1 -> 0
              [HKLM | HideDesktopIcons\NewStartPanel] | {871C5380-42A0-1069-A2EA-08002B30309D} : 1 -> 0
              [HKLM | HideDesktopIcons\NewStartPanel] | {5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0} : 1 -> 0
              [HKLM | HideDesktopIcons\NewStartPanel] | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0
              [HKLM | HideDesktopIcons\NewStartPanel] | {9343812e-1c37-4a49-a12e-4b2d810d956b} : 1 -> 0
              [HKLM | HideDesktopIcons\NewStartPanel] | {4336a54d-038b-4685-ab02-99bb52d3fb8b} : 1 -> 0
              [HKCU | Desktop] | Wallpaper : C:\Users\Public\Pictures\Sample Pictures\Dock.jpg
              Supprimé : [HKLM | policies\system] | DisableTaskMgr -> 0
              Supprimé : [HKLM | policies\system] | DisableRegistryTools -> 0

              ¤¤¤¤¤¤¤¤¤¤ Services

              [Ndisuio] | Start : 3 : Actif
              [Profsvc] | Start : 2 : Actif
              [PlugPlay] | Start : 2 : Actif
              [PEAUTH] | Start : 2 : Actif
              [Parvdm] | Start : 2 : Inactif
              [nsi] | Start : 2 : Actif
              [NLASvc] | Start : 2 : Actif
              [MPSsvc] | Start : 2 : Actif
              [MMCSS] | Start : 2 : Actif
              [luafv] | Start : 2 : Actif
              [lltdio] | Start : 2 : Actif
              [Iphlpsvc] | Start : 2 : Actif
              [IKEEXT] | Start : 2 : Actif
              [gpsvc] | Start : 2 : Actif
              [lmhosts] | Start : 2 : Actif
              [LanmanWorkstation] | Start : 2 : Actif
              [LanmanServer] | Start : 2 : Actif
              [agp440] | Start : 3 -> 2 : Inactif
              [AudioEndpointBuilder] | Start : 2 : Actif
              [Audiosrv] | Start : 2 : Actif
              [BFE] | Start : 2 : Actif
              [Bits] | Start : 2 : Actif
              [CryptSvc] | Start : 2 : Actif
              [EapHost] | Start : 3 -> 2 : Actif
              [Wlansvc] | Start : 2 : Actif
              [SharedAccess] | Start : 4 -> 2 : Inactif
              [wuauserv] | Start : 2 : Actif
              [WerSvc] | Start : 2 : Actif
              [wscsvc] | Start : 2 : Actif

              ¤¤¤¤¤¤¤¤¤¤ Internet Explorer

              [HKCU | Main] | Start Page : https://www.google.co.ma/?gws_rd=ssl -> https://www.google.com/?gws_rd=ssl
              [HKCU | Main] | Local Page : C:\Windows\system32\blank.htm
              [HKCU | Main] | Search Page : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              [HKCU | Search] | SearchAssistant : -> https://www.google.com/?gws_rd=ssl

              [HKLM | Main] | Start Page : https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fhomepage.acer.com%2frdr.aspx%3fb%3dACAW&l=040c&s=2&o=vp32&d=0209&m=aspire_2930 -> https://www.msn.com/fr-fr/?ocid=iehp
              [HKLM | Main] | Local Page : C:\Windows\System32\blank.htm
              [HKLM | Main] | Default_Search_URL : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              [HKLM | Main] | Default_Page_URL : http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0209&m=aspire_2930 -> https://www.msn.com/fr-fr/?ocid=iehp
              [HKLM | Main] | Search Page : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

              ¤

              [HKCU | PhishingFilter] | Enabled : -> 2
              [HKCU | PhishingFilter] | EnabledV8 : 1
              [HKCU | Internet Settings] | MigrateProxy : 1
              [HKCU | Internet Settings] | WarnonBadCertRecving : 1
              [HKCU | Internet Settings] | WarnOnHTTPSToHTTPRedirect : -> 1
              [HKCU | Internet Settings] | WarnonZoneCrossing : 0 -> 1
              [HKCU | Internet Settings] | AutoConfigProxy : wininet.dll

              ¤¤¤¤¤¤¤¤¤¤ DNS

              [HKLM | Tcpip\Parameters] | DhcpNameServer = 192.168.1.1
              [HKLM\CCS | Interfaces\{13D0B8B7-5D0A-4140-9055-2AD08546121B}] | DhcpNameServer -> 10.1.100.1 10.1.100.2
              [HKLM\CCS | Interfaces\{88224ADE-4B1D-4BB1-AE6C-FEF7AC6E5095}] | DhcpNameServer -> 192.168.1.1
              [HKLM\CS1 | Interfaces\{13D0B8B7-5D0A-4140-9055-2AD08546121B}] | DhcpNameServer -> 10.1.100.1 10.1.100.2
              [HKLM\CS1 | Interfaces\{88224ADE-4B1D-4BB1-AE6C-FEF7AC6E5095}] | DhcpNameServer -> 192.168.1.1
              [HKLM\CS2 | Interfaces\{13D0B8B7-5D0A-4140-9055-2AD08546121B}] | DhcpNameServer -> 10.1.100.1 10.1.100.2
              [HKLM\CS2 | Interfaces\{88224ADE-4B1D-4BB1-AE6C-FEF7AC6E5095}] | DhcpNameServer -> 192.168.1.1
              [HKLM | Tcpip\Parameters] | NameServer =

              ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

              ::1 localhost
              127.0.0.1 localhost

              ¤¤¤¤¤¤¤¤¤¤ Processus

              C:\Users\user\AppData\Local\Temp\RtkBtMnt.exe -> Processus stoppé
              C:\Windows\explorer.exe -> Processus stoppé
              C:\Windows\RtHDVCpl.exe -> Processus stoppé

              ¤¤¤¤¤¤¤¤¤¤ Traitement Fichiers | Dossiers | Registre

              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$IBPOQNY.lnk
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$R0ZQ27O
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$R3CRH0Q
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RBPOQNY.lnk
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RJP5PEO
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$ROTOW3K
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RPC5DNP
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RPP1L2S
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RQ5BYIC
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RV7L6F4
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\$RWCZF6L
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1000\desktop.ini
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-1001\desktop.ini
              Mise en quarantaine : C:\$Recycle.bin\S-1-5-21-3616354201-1143711275-3927985168-500\desktop.ini
              1. voilà:
                http://www.cijoint.fr/cjlink.php?file=cj201106/cijDsPI9BV.txt

                et merci encore pour l'aide :)
                1. si mais je pense qu'il y a un truc qui 'empeche de fonctionner en mode normal , un truc costaud
                  1. J'ai essayé de démarrer mon ordi en mode sans echec, mais ça n'a rien donné juste un ecran noir, j'ai bcp attendu apres j'ai redémarrer mon ordi en mode normal et c le mm prob aussi que l'ecran noir..Heeeeeeelp svp
                    • 1
                    • 2
                    • 3
                    • 4
                    • 5
                    • 6