[b]############################## | UsbFix V 8.181 | [Research][/b] User: User (Administrator) # DEADMAN Updated 07/01/2016 by SosVirus Started at 20:11:12 | 14/01/2016 Website : [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] Tutorial : [url=http://www.pt.usbfix.net/2014/03/tutorial-do-usbfix-scan/]http://www.pt.usbfix.net/2014/03/tutorial-do-usbfix-scan/[/url] Support : [url=http://www.sos-virus.net/]http://www.sos-virus.net/[/url] Live detection : [url=http://how-to-remove.us/]http://how-to-remove.us/[/url] Contact : [url=http://www.en.usbfix.net/contact/]http://www.en.usbfix.net/contact/[/url] [b]################## | System information |[/b] MB: Hewlett-Packard (144B) CPU: Intel(R) Core(TM) i5 CPU M 450 @ 2.40GHz GC: Intel(R) HD Graphics GC: ATI Mobility Radeon HD 5650 RAM -> [Total : 3894 Mo | Free : 1635 Mo] Bios: Hewlett-Packard Boot: Normal boot OS: Microsoft™ Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1 WB: Internet Explorer : 11.00.9600.16428 WB: Opera : 34.0.2036.25 [b]################## | Security Information |[/b] AV: Norton Internet Security [Enabled |Updated] AS: Windows Defender [[b](!) Disabled[/b] |[b](!) Outdated[/b]] AS: Norton Internet Security [Enabled |Updated] FW: Norton Internet Security [Enabled] AS: Malwarebytes Anti-Malware : 2.0.4.1028 FW: Windows Firewall [Enabled] SC: Security Center [Enabled] WU: Windows Update [Enabled] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Fixed disk # 146 Gb (84 Gb free - 58%) [] # NTFS D:\ -> Fixed disk # 785 Gb (37 Gb free - 5%) [] # NTFS F:\ -> Removable disk # 14 Gb (14 Gb free - 100%) [] # FAT32 [b]################## | Startup |[/b] F2 - HKLM\..\Winlogon : [Shell] explorer.exe F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe F2 - HKLM\..\Winlogon : [Userinit] userinit.exe, F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe, 04 - HKCU\..\Run : [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler 04 - HKCU\..\Run : [Facebook Update] "C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver 04 - HKCU\..\Run : [Spotify Web Helper] "C:\Users\User\AppData\Roaming\Spotify\SpotifyWebHelper.exe" 04 - HKCU\..\Run : [f.lux] "C:\Users\User\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow 04 - HKLM\..\Run : [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun 04 - HKLM\..\Run : [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" 04 - HKLM\..\Run : [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\" 04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe 04 - [x64] HKLM\..\Run : [IgfxTray] C:\Windows\system32\igfxtray.exe 04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\Windows\system32\hkcmd.exe 04 - [x64] HKLM\..\Run : [Persistence] C:\Windows\system32\igfxpers.exe 04 - [x64] HKLM\..\Run : [CnxtCoInstallerDefer] C:\Program Files\CONEXANT\PREINSTALL\SETUP543C22D51\KESLYN.EXE -REBOOTED_FROM_NO_ENUM_INSTALL_METHOD=1 -S 04 - [x64] HKLM\..\Run : [HPToneControl] C:\Program Files\Hewlett-Packard\HPToneControl\HPTonectl.exe 04 - [x64] HKLM\..\Run : [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe 04 - [x64] HKLM\..\Run : [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe 04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-21-3744674034-1829455987-1226542453-1000\..\Run : [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler 04 - HKU\S-1-5-21-3744674034-1829455987-1226542453-1000\..\Run : [Facebook Update] "C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver 04 - HKU\S-1-5-21-3744674034-1829455987-1226542453-1000\..\Run : [Spotify Web Helper] "C:\Users\User\AppData\Roaming\Spotify\SpotifyWebHelper.exe" 04 - HKU\S-1-5-21-3744674034-1829455987-1226542453-1000\..\Run : [f.lux] "C:\Users\User\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow 04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe [b]################## | Generic Research |[/b] Found! C:\Users\User\AppData\Roaming\home.vbe Found! C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\home.vbe Found! F:\home.vbe Found! F:\All file New.lnk Found! C:\Windows\System32\icon.ico Found! C:\Users\User\AppData\Roaming\Microsoft\home.vbe Found! D:\pulpit\backups\backup-20160113-135513-459-home.vbe Found! D:\pulpit\backups\backup-20160113-142239-467-home.vbe [b]################## | UsbFix - Information |[/b] Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]How to remove shortcut virus on flash disk (Video)[/url] Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]Shortcut virus on flash disk, What is it ?[/url] Live detection : [url=http://how-to-remove.us/]http://how-to-remove.us/[/url] [b]Analysed in 87.92 seconds[/b] [b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] |[/b]