[b]############################## | UsbFix V 8.181 | [Research][/b] User: ACE (Administrator) # ACE-HP Updated 07/01/2016 by SosVirus Started at 18:25:10 | 10/01/2016 Website : [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] Tutorial : [url=http://www.pt.usbfix.net/2014/03/tutorial-do-usbfix-scan/]http://www.pt.usbfix.net/2014/03/tutorial-do-usbfix-scan/[/url] Support : [url=http://www.sos-virus.net/]http://www.sos-virus.net/[/url] Live detection : [url=http://how-to-remove.us/]http://how-to-remove.us/[/url] Contact : [url=http://www.en.usbfix.net/contact/]http://www.en.usbfix.net/contact/[/url] [b]################## | System information |[/b] MB: Hewlett-Packard (1526) CPU: Intel(R) Core(TM)2 Duo CPU T6670 @ 2.20GHz GC: Mobile Intel(R) 4 Series Express Chipset Family RAM -> [Total : 3000 Mo | Free : 1620 Mo] Bios: Hewlett-Packard Boot: Normal boot OS: Microsoft™ Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1 WB: Internet Explorer : 11.00.9600.16428 WB: Google Chrome : 47.0.2526.106 [b]################## | Security Information |[/b] AV: avast! Antivirus [[b](!) Disabled[/b] |Updated] AS: Windows Defender [Enabled |Updated] AS: avast! Antivirus [[b](!) Disabled[/b] |Updated] FW: Windows Firewall [Enabled] SC: Security Center [Enabled] WU: Windows Update [Enabled] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Fixed disk # 281 Gb (75 Gb free - 27%) [] # NTFS D:\ -> Removable disk # 4 Gb (3 Gb free - 78%) [TOSHIBA] # FAT32 E:\ -> Fixed disk # 2 Gb (1 Gb free - 74%) [HP_TOOLS] # FAT32 [b]################## | Startup |[/b] F2 - HKLM\..\Winlogon : [Shell] explorer.exe F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe F2 - HKLM\..\Winlogon : [Userinit] userinit.exe, F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe, 04 - HKCU\..\Run : [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden 04 - HKCU\..\Run : [uTorrent] "C:\Users\ACE\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED 04 - HKCU\..\Run : [BRS] C:\Program Files (x86)\WSE_Astromenda\BRS\brs.exe -runBRS 04 - HKCU\..\Run : [BingSvc] C:\Users\ACE\AppData\Local\Microsoft\BingSvc\BingSvc.exe 04 - HKCU\..\Run : [SURVIVAL] wscript.exe //B "C:\Users\ACE\AppData\Local\Temp\SURVIVAL.vbe" 04 - HKCU\..\Run : [MerciJacquieMichel] wscript.exe //B "C:\Users\ACE\AppData\Local\Temp\MerciJacquieMichel.vbe" 04 - HKCU\..\Run : [b1dc744b25061e431af5806d6f40055c] "C:\Users\ACE\AppData\Roaming\vData.exe" .. 04 - HKCU\..\Run : [f8209e9eb2e513539d459a8bac80eb51] "C:\Users\ACE\AppData\Local\Temp\vData.exe" .. 04 - HKLM\..\Run : [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start 04 - HKLM\..\Run : [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 04 - HKLM\..\Run : [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe 04 - HKLM\..\Run : [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot 04 - HKLM\..\Run : [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe" 04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 04 - HKLM\..\Run : [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup 04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui 04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe 04 - [x64] HKLM\..\Run : [IgfxTray] C:\windows\system32\igfxtray.exe 04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\windows\system32\hkcmd.exe 04 - [x64] HKLM\..\Run : [Persistence] C:\windows\system32\igfxpers.exe 04 - [x64] HKLM\..\Run : [BTMTrayAgent] rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp 04 - [x64] HKLM\..\Run : [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe 04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-21-3906982330-3794891160-216216234-1000\..\Run : [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden 04 - HKU\S-1-5-21-3906982330-3794891160-216216234-1000\..\Run : [uTorrent] "C:\Users\ACE\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED 04 - HKU\S-1-5-21-3906982330-3794891160-216216234-1000\..\Run : [BRS] C:\Program Files (x86)\WSE_Astromenda\BRS\brs.exe -runBRS 04 - HKU\S-1-5-21-3906982330-3794891160-216216234-1000\..\Run : [BingSvc] C:\Users\ACE\AppData\Local\Microsoft\BingSvc\BingSvc.exe 04 - HKU\S-1-5-21-3906982330-3794891160-216216234-1000\..\Run : [SURVIVAL] wscript.exe //B "C:\Users\ACE\AppData\Local\Temp\SURVIVAL.vbe" 04 - HKU\S-1-5-21-3906982330-3794891160-216216234-1000\..\Run : [MerciJacquieMichel] wscript.exe //B "C:\Users\ACE\AppData\Local\Temp\MerciJacquieMichel.vbe" 04 - HKU\S-1-5-21-3906982330-3794891160-216216234-1000\..\Run : [b1dc744b25061e431af5806d6f40055c] "C:\Users\ACE\AppData\Roaming\vData.exe" .. 04 - HKU\S-1-5-21-3906982330-3794891160-216216234-1000\..\Run : [f8209e9eb2e513539d459a8bac80eb51] "C:\Users\ACE\AppData\Local\Temp\vData.exe" .. 04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04GS - McAfee Security Scan Plus.lnk : C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe [b]################## | Generic Research |[/b] Found! C:\Users\ACE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe Found! C:\Users\ACE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SURVIVAL.vbe Found! C:\Users\ACE\AppData\Local\Temp\MerciJacquieMichel.vbe Found! C:\Users\ACE\AppData\Local\Temp\SURVIVAL.vbe Found! C:\Users\ACE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\b1dc744b25061e431af5806d6f40055c.exe Found! C:\Users\ACE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0L2OVYX\b1dc744b25061e431af5806d6f40055c[1].exe Found! C:\Users\ACE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R868VRUH\b1dc744b25061e431af5806d6f40055c[1].exe Found! C:\Users\ACE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UVD9C747\b1dc744b25061e431af5806d6f40055c[1].exe Found! C:\Users\ACE\AppData\Local\Temp\808888080.exe Found! C:\Users\ACE\AppData\Local\Temp\DFSGFSDGSD.exe Found! C:\Users\ACE\AppData\Local\Temp\gfgdfgdfgdf.exe Found! C:\Users\ACE\AppData\Local\Temp\hgfhfghgff.exe Found! C:\Users\ACE\AppData\Local\Temp\jhjhgjhgj.exe Found! C:\Users\ACE\AppData\Local\Temp\MPMP00L.exe Found! C:\Users\ACE\AppData\Local\Temp\tfgdfgdgdf.exe Found! C:\Users\ACE\AppData\Roaming\vData.exe Found! HKCU\Software\b1dc744b25061e431af5806d6f40055c Found! HKU\S-1-5-21-3906982330-3794891160-216216234-1000\Software\b1dc744b25061e431af5806d6f40055c Found! HKCU\Software\f8209e9eb2e513539d459a8bac80eb51 Found! HKU\S-1-5-21-3906982330-3794891160-216216234-1000\Software\f8209e9eb2e513539d459a8bac80eb51 Found! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|b1dc744b25061e431af5806d6f40055c Found! HKU\S-1-5-21-3906982330-3794891160-216216234-1000\Software\Microsoft\Windows\CurrentVersion\Run|b1dc744b25061e431af5806d6f40055c Found! HKCU|di Found! HKU\S-1-5-21-3906982330-3794891160-216216234-1000\Software\Microsoft\Windows\CurrentVersion\Run|f8209e9eb2e513539d459a8bac80eb51 Found! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|f8209e9eb2e513539d459a8bac80eb51 Found! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SURVIVAL Found! HKU\S-1-5-21-3906982330-3794891160-216216234-1000\Software\Microsoft\Windows\CurrentVersion\Run|SURVIVAL [b]################## | UsbFix - Information |[/b] UsbFix has detected on your computer, an infection which a Keylogger function. After cleaning with UsbFix, please modify all your passwords. If you made purchases on Internet, please contact your bank to enviseager an opposition on your bank card. Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]How to remove shortcut virus on flash disk (Video)[/url] Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]Shortcut virus on flash disk, What is it ?[/url] [b]Analysed in 514.0 seconds[/b] [b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] |[/b]