[b]############################## | UsbFix V 7.941 | [Research][/b] User: Damian (Administrator) # DAMIAN-PC Updated 19/05/2015 by El Desaparecido - SosVirus Started at 07:29:55 | 20/05/2015 Website : [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] Changelog : [url=http://www.en.usbfix.net/changelog/]http://www.en.usbfix.net/changelog/[/url] Support : [url=http://www.sos-virus.net/]http://www.sos-virus.net/[/url] Live detection : [url=http://how-to-remove.us/]http://how-to-remove.us/[/url] Contact : [url=http://www.en.usbfix.net/contact/]http://www.en.usbfix.net/contact/[/url] [b]################## | System information |[/b] MB: Lenovo (INVALID) CPU: Intel(R) Core(TM)2 Duo CPU P7450 @ 2.13GHz GC: NVIDIA GeForce 9600M GS RAM -> [Total : 4063 Mo | Free : 2478 Mo] Bios: Lenovo Boot: Normal boot OS: Microsoft™ Windows 7 Professional (6.1.7601 64-Bit) Service Pack 1 WB: Internet Explorer : 11.00.9600.16428 WB: Google Chrome : 43.0.2357.65 WB: Mozilla Firefox : 36.0.4 [b]################## | Security Information |[/b] AV: Avira Antivirus [[b](!) Disabled[/b] |Updated] AS: Avira Antivirus [[b](!) Disabled[/b] |Updated] AS: Windows Defender [Enabled |Updated] FW: Windows Firewall [Enabled] SC: Security Center [Enabled] WU: Windows Update [Enabled] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Fixed disk # 44 Gb (4 Gb free - 8%) [] # NTFS D:\ -> Fixed disk # 422 Gb (154 Gb free - 37%) [] # NTFS G:\ -> Removable disk # 7 Gb (7 Gb free - 100%) [] # FAT32 [b]################## | Autorun |[/b] G:\Removable Drive (8GB).lnk -> G:\ \~$b.myn [b]################## | Startup |[/b] F2 - HKLM\..\Winlogon : [Shell] explorer.exe F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe F2 - HKLM\..\Winlogon : [Userinit] userinit.exe F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\System32\Userinit.exe, F3 - HKCU\..\Windows : [Load] C:\ProgramData\msrfft.exe 04 - HKCU\..\Run : [OneDrive] "C:\Users\Damian\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background 04 - HKCU\..\Run : [DAEMON Tools Lite] "D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun 04 - HKCU\..\Run : [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR 04 - HKCU\..\Run : [Skype] "D:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun 04 - HKCU\..\RunOnce : [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_17_0_0_169_Plugin.exe -update plugin 04 - HKLM\..\Run : [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" 04 - HKLM\..\Run : [GrooveMonitor] "D:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" 04 - HKLM\..\Run : [avgnt] "D:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min 04 - HKLM\..\Run : [QuickTime Task] "D:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime 04 - HKLM\..\Run : [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe 04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" 04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe 04 - [x64] HKLM\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe 04 - [x64] HKLM\..\Run : [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe 04 - [x64] HKLM\..\Run : [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe" 04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-21-1461562640-103210102-4150413856-1000\..\Run : [OneDrive] "C:\Users\Damian\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background 04 - HKU\S-1-5-21-1461562640-103210102-4150413856-1000\..\Run : [DAEMON Tools Lite] "D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun 04 - HKU\S-1-5-21-1461562640-103210102-4150413856-1000\..\Run : [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR 04 - HKU\S-1-5-21-1461562640-103210102-4150413856-1000\..\Run : [Skype] "D:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun 04 - HKU\S-1-5-21-1461562640-103210102-4150413856-1003\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-21-1461562640-103210102-4150413856-1000\..\RunOnce : [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_17_0_0_169_Plugin.exe -update plugin 04 - HKU\S-1-5-21-1461562640-103210102-4150413856-1003\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe [b]################## | Generic Research |[/b] Found! G:\Removable Drive (8GB).lnk Found! G:\ \~$b.myn Found! C:\ProgramData\msrfft.exe Found! C:\Users\All Users\msrfft.exe [b]################## | Registry |[/b] Found! HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows|load (C:\ProgramData\msrfft.exe) [b]################## | UsbFix - Information |[/b] Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]How to remove shortcut virus on flash disk (Video)[/url] Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]Shortcut virus on flash disk, What is it ?[/url] Live detection : [url=http://how-to-remove.us/]http://how-to-remove.us/[/url] [b]################## | Attrib - Restore |[/b] [b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] |[/b]