[b]############################## | UsbFix V 7.932 | [Research][/b] User: Yasmine (Administrator) # YASMINE-HP Updated 04/05/2015 by El Desaparecido - SosVirus Started at 15:29:56 | 05/05/2015 Website : [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] Changelog : [url=http://www.en.usbfix.net/changelog/]http://www.en.usbfix.net/changelog/[/url] Support : [url=http://www.sos-virus.net/]http://www.sos-virus.net/[/url] Live detection : [url=http://how-to-remove.us/]http://how-to-remove.us/[/url] Contact : [url=http://www.en.usbfix.net/contact/]http://www.en.usbfix.net/contact/[/url] [b]################## | System information |[/b] MB: Hewlett-Packard (1693) CPU: Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz RAM -> [Total : 3894 Mo | Free : 1752 Mo] Bios: Hewlett-Packard Boot: Normal boot OS: Microsoft™ Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1 WB: Internet Explorer : 11.00.9600.16428 WB: Google Chrome : 35.0.1916.153 WB: Mozilla Firefox : 37.0.2 [b]################## | Security Information |[/b] AV: avast! Antivirus [Enabled |Updated] AS: Windows Defender [Enabled |Updated] AS: avast! Antivirus [Enabled |Updated] AS: Malwarebytes Anti-Malware : 1.75.0001 FW: Windows Firewall [Enabled] SC: Security Center [Enabled] WU: Windows Update [Enabled] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Fixed disk # 451 Gb (5 Gb free - 1%) [] # NTFS D:\ -> Fixed disk # 14 Gb (2 Gb free - 12%) [RECOVERY] # NTFS F:\ -> Removable disk # 15 Gb (1 Gb free - 10%) [] # FAT32 G:\ -> Removable disk # 7 Gb (7 Gb free - 100%) [] # FAT32 H:\ -> Fixed disk # 466 Gb (414 Gb free - 89%) [TOSHIBA EXT] # NTFS [b]################## | Autorun |[/b] [b]################## | Startup |[/b] F2 - HKLM\..\Winlogon : [Shell] explorer.exe F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe F2 - HKLM\..\Winlogon : [Userinit] userinit.exe, F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe, 04 - HKCU\..\Run : [E06FDXRC_226466] "C:\Program Files (x86)\Microsoft Encarta\Collection Microsoft Encarta 2006\EDICT.EXE" -m 04 - HKCU\..\Run : [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" 04 - HKLM\..\Run : [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 04 - HKLM\..\Run : [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe 04 - HKLM\..\Run : [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe 04 - HKLM\..\Run : [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" 04 - HKLM\..\Run : [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe 04 - HKLM\..\Run : [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe 04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui 04 - HKLM\..\Run : [Kepard] "C:\Program Files (x86)\Kepard\Kepard.exe" tray 04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 04 - [x64] HKLM\..\Run : [IgfxTray] C:\Windows\system32\igfxtray.exe 04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\Windows\system32\hkcmd.exe 04 - [x64] HKLM\..\Run : [Persistence] C:\Windows\system32\igfxpers.exe 04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe 04 - [x64] HKLM\..\Run : [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe 04 - [x64] HKLM\..\Run : [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" 04 - [x64] HKLM\..\Run : [VideoLAN] C:\WINDOWS\system32\wscript.exe /e:VBScript.Encode D:\$RECYCLEBIN\Vlc.rar 04 - [x64] HKLM\..\Run : [C-cleaner] C:\WINDOWS\system32\wscript.exe /e:VBScript.Encode D:\$RECYCLEBIN\Adobe.rar 04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-21-2825522158-1354563-1962445389-1000\..\Run : [E06FDXRC_226466] "C:\Program Files (x86)\Microsoft Encarta\Collection Microsoft Encarta 2006\EDICT.EXE" -m 04 - HKU\S-1-5-21-2825522158-1354563-1962445389-1000\..\Run : [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" 04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04GS - C-cleaner.lnk : C:\Windows\system32\wscript.exe 04GS - VideoLAN.lnk : C:\Windows\system32\wscript.exe [b]################## | Generic Research |[/b] Found! C:\Users\Yasmine\AppData\Local\Temp\help.vbe Found! C:\Users\Yasmine\AppData\Local\Temp\Facebook.exe Found! D:\Dossier.lnk Found! F:\Dossier.lnk Found! F:\Nouveau dossier.lnk Found! G:\Dossier.lnk Found! G:\Nouveau dossier.lnk Found! C:\$RECYCLEBIN\06 Found! C:\$RECYCLEBIN\Adobe.rar Found! C:\$RECYCLEBIN\Skype.rar Found! C:\$RECYCLEBIN\Vlc.rar Found! C:\$RECYCLEBIN Found! C:\Users\Yasmine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\C-cleaner.lnk Found! C:\Users\Yasmine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VideoLAN.lnk Found! F:\Recycler\S-1-5-76-5738352767-2665678015-163002121-7075\QTkslSkA.exe Found! F:\Recycler\S-1-5-76-5738352767-2665678015-163002121-7075\uHGSyjsC.cpl Found! F:\Recycler\S-1-5-76-5738352767-2665678015-163002121-7075 Found! D:\$RECYCLEBIN\01 Found! D:\$RECYCLEBIN\03 Found! D:\$RECYCLEBIN\05 Found! D:\$RECYCLEBIN\06 Found! D:\$RECYCLEBIN\Adobe.rar Found! D:\$RECYCLEBIN\Skype.rar Found! D:\$RECYCLEBIN\Vlc.rar Found! D:\$RECYCLEBIN Found! F:\$RECYCLEBIN\Skype.rar Found! F:\$RECYCLEBIN\Vlc.rar Found! F:\$RECYCLEBIN\Adobe.rar Found! F:\$RECYCLEBIN\06 Found! F:\$RECYCLEBIN Found! G:\$RECYCLEBIN\Skype.rar Found! G:\$RECYCLEBIN\Vlc.rar Found! G:\$RECYCLEBIN\Adobe.rar Found! G:\$RECYCLEBIN\06 Found! G:\$RECYCLEBIN Found! F:\RECYCLER\S-1-5-76-5738352767-2665678015-163002121-7075\QTkslSkA.exe [b]################## | Registry |[/b] Found! [x64] HKLM\Software\Microsoft\Windows\CurrentVersion\Run|C-cleaner Found! [x64] HKLM\Software\Microsoft\Windows\CurrentVersion\Run|VideoLAN [b]################## | UsbFix - Information |[/b] Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]How to remove shortcut virus on flash disk (Video)[/url] Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]Shortcut virus on flash disk, What is it ?[/url] Live detection : [url=http://how-to-remove.us/]http://how-to-remove.us/[/url] [b]################## | Attrib - Restore |[/b] [b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] |[/b]