comment ca elle est obsotèle?
voila le rapport qu'on m a donné hier avant l'apparition du problème
############################## | UsbFix V 7.155 | [Recherche]
Utilisateur: ayoub (Administrateur) # ASUS-PC
Mis à jour le 16/12/2013 par El Desaparecido - Team SosVirus
Lancé à 21:56:23 | 12/05/2014
Site Web :
http://www.usbfix.net
Forum :
http://www.sosvirus.net/
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.usbfix.net/contact/
PC: ASUSTeK COMPUTER INC. (X550LA)
CPU: Intel(R) Core(TM) i5-4200U CPU @ 1.60GHz
RAM - [Total : 3980 | Free : 2410]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 7 Professionnel (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 8.0.7601.17514
WB: Google Chrome : 34.0.1847.131
WB: Mozilla Firefox : 28.0
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [Enabled | (!) Outdated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) - Disque fixe # 152 Go (113 Go libre(s) - 75%) [] # NTFS
D:\ - Disque fixe # 314 Go (236 Go libre(s) - 75%) [] # NTFS
E:\ - CD-ROM
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 532 |ParentID: 524)
C:\Windows\system32\wininit.exe (ID: 600 |ParentID: 524)
C:\Windows\system32\csrss.exe (ID: 620 |ParentID: 612)
C:\Windows\system32\services.exe (ID: 688 |ParentID: 600)
C:\Windows\system32\lsass.exe (ID: 696 |ParentID: 600)
C:\Windows\system32\lsm.exe (ID: 704 |ParentID: 600)
C:\Windows\system32\winlogon.exe (ID: 740 |ParentID: 612)
C:\Windows\system32\svchost.exe (ID: 840 |ParentID: 688)
C:\Windows\system32\svchost.exe (ID: 916 |ParentID: 688)
C:\Windows\system32\atiesrxx.exe (ID: 980 |ParentID: 688)
C:\Windows\System32\svchost.exe (ID: 352 |ParentID: 688)
C:\Windows\System32\svchost.exe (ID: 548 |ParentID: 688)
C:\Windows\system32\svchost.exe (ID: 508 |ParentID: 688)
C:\Windows\system32\AUDIODG.EXE (ID: 1048 |ParentID: 352)
C:\Windows\system32\svchost.exe (ID: 1108 |ParentID: 688)
C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (ID: 1184 |ParentID: 688)
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ID: 1220 |ParentID: 1184)
C:\Windows\system32\svchost.exe (ID: 1256 |ParentID: 688)
C:\Windows\system32\atieclxx.exe (ID: 1272 |ParentID: 980)
C:\Windows\System32\spoolsv.exe (ID: 1476 |ParentID: 688)
C:\Windows\system32\svchost.exe (ID: 1504 |ParentID: 688)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1636 |ParentID: 688)
C:\Windows\system32\taskhost.exe (ID: 1644 |ParentID: 688)
C:\Windows\system32\DptfParticipantProcessorService.exe (ID: 1796 |ParentID: 688)
C:\Windows\system32\DptfPolicyConfigTDPService.exe (ID: 1836 |ParentID: 688)
C:\Windows\system32\DptfPolicyCriticalService.exe (ID: 1884 |ParentID: 688)
C:\Windows\system32\Dwm.exe (ID: 1892 |ParentID: 548)
C:\Program Files\ma-config.com\MaConfigAgent.exe (ID: 1960 |ParentID: 688)
C:\Windows\Explorer.EXE (ID: 1992 |ParentID: 1856)
C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe (ID: 1304 |ParentID: 688)
C:\Windows\system32\taskeng.exe (ID: 1168 |ParentID: 508)
C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe (ID: 2356 |ParentID: 688)
C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\SafetyNutManager.exe (ID: 2396 |ParentID: 688)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID: 2480 |ParentID: 1992)
C:\Windows\System32\igfxtray.exe (ID: 2488 |ParentID: 1992)
C:\Windows\System32\hkcmd.exe (ID: 2500 |ParentID: 1992)
C:\Windows\System32\igfxpers.exe (ID: 2516 |ParentID: 1992)
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ID: 2532 |ParentID: 1992)
C:\Windows\system32\igfxsrvc.exe (ID: 2540 |ParentID: 840)
C:\Program Files (x86)\Skype\Phone\Skype.exe (ID: 2904 |ParentID: 1992)
C:\Program Files\Supercopier\supercopier.exe (ID: 2924 |ParentID: 1992)
C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\SafetyNutManager.exe (ID: 3020 |ParentID: 2396)
C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\safetynut.exe (ID: 3040 |ParentID: 2396)
C:\Windows\system32\svchost.exe (ID: 900 |ParentID: 688)
C:\Windows\system32\SearchIndexer.exe (ID: 3092 |ParentID: 688)
C:\Users\ayoub\AppData\Roaming\uTorrent\uTorrent.exe (ID: 3136 |ParentID: 1992)
C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (ID: 3324 |ParentID: 1992)
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ID: 3508 |ParentID: 3280)
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (ID: 3520 |ParentID: 3280)
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (ID: 3884 |ParentID: 1168)
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 2896 |ParentID: 2616)
C:\Windows\system32\taskhost.exe (ID: 3864 |ParentID: 688)
C:\Windows\system32\svchost.exe (ID: 328 |ParentID: 688)
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 3448 |ParentID: 688)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 2156 |ParentID: 840)
C:\Windows\system32\sppsvc.exe (ID: 1148 |ParentID: 688)
C:\Windows\System32\svchost.exe (ID: 568 |ParentID: 688)
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ID: 1784 |ParentID: 688)
C:\Program Files\Alwil Software\Avast5\avastUI.exe (ID: 4132 |ParentID: 4036)
C:\Program Files (x86)\Windows Media Player\wmplayer.exe (ID: 5112 |ParentID: 1992)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4252 |ParentID: 1992)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4848 |ParentID: 4252)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3132 |ParentID: 4252)
C:\Windows\system32\taskeng.exe (ID: 676 |ParentID: 508)
C:\UsbFix\Go.exe (ID: 3100 |ParentID: 4072)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
04 - HKLM\SOFTWARE | Run : [TkBellExe] - "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
04 - HKLM\SOFTWARE | Run : [avast5] - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [TkBellExe] - "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
04 - HKLM\SOFTWARE\wow6432Node | Run : [avast5] - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-1969747121-3965189580-769251239-1000\SOFTWARE | Run : [Badoo Desktop] - C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe
04 - HKU\S-1-5-21-1969747121-3965189580-769251239-1000\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-21-1969747121-3965189580-769251239-1000\SOFTWARE | Run : [ultracopier] - "C:\Program Files\Supercopier\supercopier.exe"
04 - HKU\S-1-5-21-1969747121-3965189580-769251239-1000\SOFTWARE | Run : [uTorrent] - "C:\Users\ayoub\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Recherche générique |
################## | Registre |
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
################## | Vaccin |
D:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
http://www.usbfix.net -
http://www.sosvirus.net |