[b]############################## | UsbFix V 7.178 | [Research][/b] User: 98 (Administrator) # XX-035E39113BC4 Updated 08/08/2014 by El Desaparecido - SosVirus Started at 15:47:56 | 27/08/2014 Website : [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] Changelog : [url=http://www.en.usbfix.net/changelog/]http://www.en.usbfix.net/changelog/[/url] Support : [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] Upload Malware : [url=http://www.sosvirus.net/upload_malware.php]http://www.sosvirus.net/upload_malware.php[/url] Contact : [url=http://www.en.usbfix.net/contact/]http://www.en.usbfix.net/contact/[/url] [b]################## | System information |[/b] CPU: Intel(R) Pentium(R) Dual CPU E2180 @ 2.00GHz RAM -> [Total : 1022 Mo | Free : 481 Mo] Boot: Normal boot OS: Microsoft Windows XP (5.1.2600 32-Bit) Dodatek Service Pack 3 WB: Internet Explorer : 8.00.6001.18702 WB: Google Chrome : 28.0.1500.95 WB: Mozilla Firefox : 31.0 [b]################## | Security Information |[/b] FW: Windows Firewall [[b](!) Disabled[/b]] SC: Security Center [Enabled] WU: Windows Update [Enabled] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Fixed disk # 98 Gb (76 Gb free - 78%) [] # NTFS E:\ -> Removable disk # 7 Gb (5 Gb free - 71%) [Sony_8GR] # FAT32 G:\ -> Fixed disk # 368 Gb (30 Gb free - 8%) [] # NTFS [b]################## | Autorun |[/b] [b]################## | Regedit Run |[/b] F2 - HKLM\..\Winlogon : [Shell] Explorer.exe F2 - HKLM\..\Winlogon : [Userinit] C:\WINDOWS\system32\userinit.exe, 04 - HKCU\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 04 - HKCU\..\Run : [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" 04 - HKCU\..\Run : [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 04 - HKCU\..\Run : [Facebook Update] "C:\Documents and Settings\98\Ustawienia lokalne\Dane aplikacji\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver 04 - HKCU\..\Run : [GG] "C:\Documents and Settings\98\Ustawienia lokalne\Dane aplikacji\GG\Application\gghub.exe" 04 - HKCU\..\Run : [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun 04 - HKCU\..\Run : [uTorrent] "G:\Łukasz\torrent\uTorrent.exe" /MINIMIZED 04 - HKCU\..\Run : [99] wscript.exe //B "C:\Documents and Settings\98\Dane aplikacji\99.vbs" 04 - HKLM\..\Run : [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun 04 - HKLM\..\Run : [RTHDCPL] RTHDCPL.EXE 04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" 04 - HKLM\..\Run : [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui 04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" 04 - HKU\S-1-5-19\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE 04 - HKU\S-1-5-20\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [Facebook Update] "C:\Documents and Settings\98\Ustawienia lokalne\Dane aplikacji\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [GG] "C:\Documents and Settings\98\Ustawienia lokalne\Dane aplikacji\GG\Application\gghub.exe" 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [uTorrent] "G:\Łukasz\torrent\uTorrent.exe" /MINIMIZED 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [99] wscript.exe //B "C:\Documents and Settings\98\Dane aplikacji\99.vbs" 04 - HKU\S-1-5-18\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE [b]################## | Generic Research |[/b] Found! G:\Thumbs.db Found! E:\Autorun.inf [b]################## | Registry |[/b] [b]################## | UsbFix - Information |[/b] Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]How to remove shortcut virus on flash disk (Video)[/url] Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]Shortcut virus on flash disk, What is it ?[/url] [b]################## | Hijack |[/b] Hijacked! [SH] E:\italia.jpg Hijacked! [SH] E:\italia2.JPG Hijacked! [SHD] E:\normany Hijacked! [SH] E:\Bibliografia2.odt Hijacked! [SH] E:\20_Kartagina i Italia.jpg Hijacked! [SH] E:\Bibliografia3.odt Hijacked! [SH] E:\19_Italia około roku 500 p.n.e.jpg Hijacked! [SH] E:\cos talikego.jpg Hijacked! [SH] E:\imperium romanum.jpg Hijacked! [SH] E:\lista.jpg Hijacked! [SH] E:\Shepherd_Map_of_Ancient_Italy,_Northern_Part.jpg Hijacked! [SH] E:\Shepherd-c-030-031.jpg Hijacked! [SH] E:\Ballada.mp3 Hijacked! [SH] E:\Dlaczego Normanowie sialalala4.odt Hijacked! [SH] E:\Dlaczego Normanowie sialalala42.doc Hijacked! [SH] E:\Lekcja 5.MP3 Hijacked! [SH] E:\Biblio Dąbrowa.odt Hijacked! [SH] E:\BOOTEX.LOG Hijacked! [SHD] E:\S.O.A.D Hijacked! [SHD] E:\pdfy Hijacked! [SHD] E:\konglomerat Hijacked! [SHD] E:\Podkłady Hijacked! [SHD] E:\Lekcje Hijacked! [SHD] E:\Kodeks Hijacked! [SH] E:\podanie o przeniesienie233.doc Hijacked! [SH] E:\podanie o przeniesienie234 inny format.odt Hijacked! [H] E:\AUTORUN.INF Hijacked! [SHD] E:\Bity Hijacked! [SHD] E:\Łacina Hijacked! [SH] E:\Darkwarez.txt Hijacked! [SH] E:\Nie pytam.m4a Hijacked! [SH] E:\Bibliografia.odt [b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] |[/b]