voila le rapport après installation de usbFix.
que devrai je faire après?
merci beaucoup
############################## | UsbFix V 7.161 | [Recherche]
Utilisateur: hanane (Administrateur) # HANANE-PC
Mis à jour le 15/01/2014 par El Desaparecido - Team SosVirus
Lancé à 19:58:26 | 24/01/2014
Site Web :
http://www.usbfix.net
Changelog :
http://www.usbfix.net/maj/
Support :
http://www.sosvirus.net/
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.usbfix.net/contact/
PC: Acer (JV50 )
CPU: Pentium(R) Dual-Core CPU T4500 @ 2.30GHz
RAM - [Total : 4091 Mo| Free : 1564 Mo]
Bios: Phoenix Technologies LTD
Boot: Normal boot
OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 11.0.9600.16476
WB: Google Chrome : 32.0.1700.76
WB: Mozilla Firefox : 26.0
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) - Disque fixe # 121 Go (25 Go libre(s) - 21%) [ACER] # NTFS
D:\ - CD-ROM
E:\ - Disque fixe # 213 Go (131 Go libre(s) - 61%) [nadia] # NTFS
F:\ - CD-ROM
J:\ - Disque amovible # 2 Go (2 Go libre(s) - 100%) [] # FAT
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 512 |ParentID: 448)
C:\Windows\system32\wininit.exe (ID: 584 |ParentID: 448)
C:\Windows\system32\csrss.exe (ID: 596 |ParentID: 576)
C:\Windows\system32\services.exe (ID: 640 |ParentID: 584)
C:\Windows\system32\lsass.exe (ID: 656 |ParentID: 584)
C:\Windows\system32\lsm.exe (ID: 664 |ParentID: 584)
C:\Windows\system32\svchost.exe (ID: 776 |ParentID: 640)
C:\Windows\system32\svchost.exe (ID: 888 |ParentID: 640)
C:\Windows\system32\winlogon.exe (ID: 924 |ParentID: 576)
C:\Windows\system32\atiesrxx.exe (ID: 952 |ParentID: 640)
C:\Windows\System32\svchost.exe (ID: 1020 |ParentID: 640)
C:\Windows\System32\svchost.exe (ID: 396 |ParentID: 640)
C:\Windows\system32\svchost.exe (ID: 448 |ParentID: 640)
C:\Windows\system32\svchost.exe (ID: 732 |ParentID: 640)
C:\Windows\system32\atieclxx.exe (ID: 1220 |ParentID: 952)
C:\Windows\system32\svchost.exe (ID: 1252 |ParentID: 640)
C:\Windows\system32\svchost.exe (ID: 1420 |ParentID: 640)
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ID: 1496 |ParentID: 640)
C:\Program Files (x86)\WinZipper\winzipersvc.exe (ID: 1828 |ParentID: 640)
C:\ProgramData\WPM\wprotectmanager.exe (ID: 1872 |ParentID: 640)
C:\Windows\System32\spoolsv.exe (ID: 1984 |ParentID: 640)
C:\Windows\system32\taskhost.exe (ID: 1232 |ParentID: 640)
C:\Program Files\LSI SoftModem\agr64svc.exe (ID: 1632 |ParentID: 640)
C:\Windows\system32\Dwm.exe (ID: 1756 |ParentID: 396)
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (ID: 2024 |ParentID: 640)
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (ID: 2064 |ParentID: 640)
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (ID: 2088 |ParentID: 640)
C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (ID: 2140 |ParentID: 640)
C:\Windows\Explorer.EXE (ID: 2148 |ParentID: 1544)
C:\Program Files (x86)\Borland\InterBase\bin\ibguard.exe (ID: 2204 |ParentID: 640)
C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe (ID: 2240 |ParentID: 640)
C:\Program Files (x86)\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe (ID: 2264 |ParentID: 640)
C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe (ID: 2292 |ParentID: 640)
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (ID: 2332 |ParentID: 640)
C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (ID: 2368 |ParentID: 640)
C:\Program Files\PostgreSQL\9.2\bin\pg_ctl.exe (ID: 2456 |ParentID: 640)
C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe (ID: 2524 |ParentID: 640)
C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (ID: 2664 |ParentID: 2456)
C:\Windows\system32\conhost.exe (ID: 2672 |ParentID: 512)
C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (ID: 2720 |ParentID: 2664)
C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (ID: 2744 |ParentID: 640)
C:\Program Files\Acer\Acer Updater\UpdaterService.exe (ID: 2776 |ParentID: 640)
C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (ID: 2856 |ParentID: 2664)
C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (ID: 2864 |ParentID: 2664)
C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (ID: 2872 |ParentID: 2664)
C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (ID: 2880 |ParentID: 2664)
C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (ID: 2888 |ParentID: 2664)
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (ID: 2920 |ParentID: 640)
C:\Program Files (x86)\Borland\InterBase\bin\ibserver.exe (ID: 2712 |ParentID: 640)
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (ID: 3300 |ParentID: 2148)
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (ID: 3356 |ParentID: 2148)
C:\Windows\System32\wscript.exe (ID: 3388 |ParentID: 2148)
C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (ID: 3500 |ParentID: 2744)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 3568 |ParentID: 776)
C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (ID: 3668 |ParentID: 2148)
C:\Windows\system32\wbem\unsecapp.exe (ID: 3716 |ParentID: 776)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 3808 |ParentID: 776)
C:\Users\hanane\AppData\Roaming\Dropbox\bin\Dropbox.exe (ID: 3912 |ParentID: 2148)
C:\Program Files (x86)\Google\Google Talk\googletalk.exe (ID: 3920 |ParentID: 3644)
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (ID: 3932 |ParentID: 3644)
C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ID: 4000 |ParentID: 3644)
C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (ID: 3344 |ParentID: 2024)
C:\Windows\system32\SearchIndexer.exe (ID: 3820 |ParentID: 640)
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (ID: 3444 |ParentID: 5032)
C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (ID: 576 |ParentID: 3444)
C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (ID: 4200 |ParentID: 3444)
C:\Windows\System32\svchost.exe (ID: 4304 |ParentID: 640)
C:\Windows\system32\svchost.exe (ID: 3376 |ParentID: 640)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3948 |ParentID: 2148)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 1660 |ParentID: 3948)
C:\PROGRA~2\Systran\4_0\Premium\SYSTRA~1.EXE (ID: 3216 |ParentID: 776)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ID: 3708 |ParentID: 640)
C:\Program Files (x86)\Micro Application\38 Dictionnaires et Recueils de Correspondance\MediaDico38.exe (ID: 4684 |ParentID: 5036)
C:\Program Files (x86)\Micro Application\38 Dictionnaires et Recueils de Correspondance\RAC38.exe (ID: 5912 |ParentID: 5036)
C:\Windows\system32\spool\DRIVERS\x64\3\E_IAMTEDE.EXE (ID: 4872 |ParentID: 1052)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 2440 |ParentID: 3948)
C:\Users\hanane\AppData\Local\iLivid\iLivid.exe (ID: 1528 |ParentID: 2148)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6108 |ParentID: 3948)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 5140 |ParentID: 3948)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6740 |ParentID: 3948)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6216 |ParentID: 3948)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 5840 |ParentID: 3948)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 748 |ParentID: 3948)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4800 |ParentID: 3948)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6084 |ParentID: 3948)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6428 |ParentID: 3948)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 5004 |ParentID: 3948)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6840 |ParentID: 3948)
C:\Windows\system32\DllHost.exe (ID: 6320 |ParentID: 776)
C:\Windows\system32\SearchProtocolHost.exe (ID: 4100 |ParentID: 3820)
C:\Windows\system32\SearchFilterHost.exe (ID: 5356 |ParentID: 3820)
################## | Regedit Run |
04 - HKLM\..\Run : [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
04 - HKLM\..\Run : [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe /autostart
04 - HKLM\..\Run : [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
04 - HKLM\..\Run : [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
04 - HKLM\..\Run : [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
04 - HKLM\..\RunOnce : []
04 - HKLM\..\Policies\Explorer\run : [Updates] "C:\Windows\svchost .exe" /e:VBScript.Encode "C:\Users\hanane\AppData\Roaming\Microsoft\SYSTEM\cste"
04 - HKLM64\..\Run : [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe
04 - HKLM64\..\Run : [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
04 - HKLM64\..\Run : [exsgvxppbd] wscript.exe //B "C:\Users\hanane\AppData\Roaming\exsgvxppbd..vbs"
04 - HKLM64\..\Policies\Explorer\run : [Updates] "C:\Windows\svchost .exe" /e:VBScript.Encode "C:\Users\hanane\AppData\Roaming\Microsoft\SYSTEM\cste"
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-2276692227-1323890955-1174232378-1000\..\Run : [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
04 - HKU\S-1-5-21-2276692227-1323890955-1174232378-1000\..\Run : [exsgvxppbd] wscript.exe //B "C:\Users\hanane\AppData\Roaming\exsgvxppbd..vbs"
04 - HKU\S-1-5-21-2276692227-1323890955-1174232378-1000\..\Run : [ccleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
################## | Recherche générique |
Présent! C:\Users\hanane\AppData\Roaming\exsgvxppbd..vbs
Présent! C:\Users\hanane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\exsgvxppbd..vbs
Présent! J:\exsgvxppbd..vbs
Présent! J:\MEMSTICK.lnk
Présent! J:\MSTK_PRO.lnk
Présent! C:\Windows\svchost .exe
Présent! C:\Users\hanane\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes\Startup\exsgvxppbd..vbs
Présent! C:\Users\hanane\Application Data\exsgvxppbd..vbs
Présent! C:\Users\hanane\Application Data\Microsoft\Windows\Start Menu\Programmes\Startup\exsgvxppbd..vbs
Présent! C:\Users\hanane\Application Data\Microsoft\Windows\Start Menu\Programs\Startup\exsgvxppbd..vbs
################## | Registre |
Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|EnableLUA - 0
Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin - 0
Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Updates
Présent! HKU\S-1-5-21-2276692227-1323890955-1174232378-1000\Software\Microsoft\Windows\CurrentVersion\Run|exsgvxppbd
Présent! HKLM64\Software\Microsoft\Windows\CurrentVersion\Run|exsgvxppbd
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|exsgvxppbd
################## | Vaccin |
################## | E.O.F |
http://www.usbfix.net -
http://www.sosvirus.net |