[b]############################## | UsbFix V 7.178 | [Research][/b] User: 98 (Administrator) # XX-035E39113BC4 Updated 08/08/2014 by El Desaparecido - SosVirus Started at 15:38:42 | 27/08/2014 Website : [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] Changelog : [url=http://www.en.usbfix.net/changelog/]http://www.en.usbfix.net/changelog/[/url] Support : [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] Upload Malware : [url=http://www.sosvirus.net/upload_malware.php]http://www.sosvirus.net/upload_malware.php[/url] Contact : [url=http://www.en.usbfix.net/contact/]http://www.en.usbfix.net/contact/[/url] [b]################## | System information |[/b] CPU: Intel(R) Pentium(R) Dual CPU E2180 @ 2.00GHz RAM -> [Total : 1022 Mo | Free : 358 Mo] Boot: Normal boot OS: Microsoft Windows XP (5.1.2600 32-Bit) Dodatek Service Pack 3 WB: Internet Explorer : 8.00.6001.18702 WB: Google Chrome : 28.0.1500.95 WB: Mozilla Firefox : 31.0 [b]################## | Security Information |[/b] FW: Windows Firewall [[b](!) Disabled[/b]] SC: Security Center [Enabled] WU: Windows Update [Enabled] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Fixed disk # 98 Gb (76 Gb free - 78%) [] # NTFS E:\ -> Removable disk # 15 Gb (12 Gb free - 84%) [] # FAT32 G:\ -> Fixed disk # 368 Gb (30 Gb free - 8%) [] # NTFS H:\ -> Removable disk # 4 Gb (571 Mb free - 15%) [] # FAT32 [b]################## | Autorun |[/b] [b]################## | Regedit Run |[/b] F2 - HKLM\..\Winlogon : [Shell] Explorer.exe F2 - HKLM\..\Winlogon : [Userinit] C:\WINDOWS\system32\userinit.exe, 04 - HKCU\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 04 - HKCU\..\Run : [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" 04 - HKCU\..\Run : [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 04 - HKCU\..\Run : [Facebook Update] "C:\Documents and Settings\98\Ustawienia lokalne\Dane aplikacji\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver 04 - HKCU\..\Run : [GG] "C:\Documents and Settings\98\Ustawienia lokalne\Dane aplikacji\GG\Application\gghub.exe" 04 - HKCU\..\Run : [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun 04 - HKCU\..\Run : [uTorrent] "G:\Łukasz\torrent\uTorrent.exe" /MINIMIZED 04 - HKCU\..\Run : [99] wscript.exe //B "C:\Documents and Settings\98\Dane aplikacji\99.vbs" 04 - HKLM\..\Run : [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun 04 - HKLM\..\Run : [RTHDCPL] RTHDCPL.EXE 04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" 04 - HKLM\..\Run : [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui 04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" 04 - HKU\S-1-5-19\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE 04 - HKU\S-1-5-20\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [Facebook Update] "C:\Documents and Settings\98\Ustawienia lokalne\Dane aplikacji\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [GG] "C:\Documents and Settings\98\Ustawienia lokalne\Dane aplikacji\GG\Application\gghub.exe" 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [uTorrent] "G:\Łukasz\torrent\uTorrent.exe" /MINIMIZED 04 - HKU\S-1-5-21-790525478-1343024091-725345543-1003\..\Run : [99] wscript.exe //B "C:\Documents and Settings\98\Dane aplikacji\99.vbs" 04 - HKU\S-1-5-18\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE [b]################## | Generic Research |[/b] Found! G:\Thumbs.db Found! E:\Autorun.inf [b]################## | Registry |[/b] [b]################## | UsbFix - Information |[/b] Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]How to remove shortcut virus on flash disk (Video)[/url] Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]Shortcut virus on flash disk, What is it ?[/url] [b]################## | Hijack |[/b] Hijacked! [SHD] E:\Images Hijacked! [SHD] E:\Videos Hijacked! [SHD] E:\Sounds Hijacked! [SHD] E:\Others Hijacked! [H] E:\AUTORUN.INF Hijacked! [SHD] H:\PIONEER Hijacked! [SHD] H:\26.12.2013 Hijacked! [SHD] H:\Mohito 14.06.2013 Hijacked! [SHD] H:\Otrzesiny licealne Hijacked! [SHD] H:\Stacja Hijacked! [SHD] H:\Electronic Road Hijacked! [SHD] H:\vv Hijacked! [SHD] H:\24.05 Hijacked! [SHD] H:\4.07.2014 Hijacked! [SHD] H:\12.07 Hijacked! [SHD] H:\SAIBOOT Hijacked! [SHD] H:\Electronic Road vol 5 Hijacked! [SHD] H:\flash ogródek Hijacked! [SHD] H:\inaczej Hijacked! [SHD] H:\3.08 Hijacked! [SHD] H:\Mixed.In.Key.v2.5-AGAiN Hijacked! [SHD] H:\house Hijacked! [SHD] H:\VirtualDJ [b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] |[/b]