[b]############################## | UsbFix V 7.181 | [Clean][/b]

User: Lucie (Administrator) # C02-316B
Updated 31/08/2014 by El Desaparecido - SosVirus
Started at 20:49:07 | 21/05/2015

Website : [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url]
Changelog : [url=http://www.en.usbfix.net/changelog/]http://www.en.usbfix.net/changelog/[/url]
Support : [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url]
Upload Malware : [url=http://www.sosvirus.net/upload_malware.php]http://www.sosvirus.net/upload_malware.php[/url]
Contact : [url=http://www.en.usbfix.net/contact/]http://www.en.usbfix.net/contact/[/url]

[b]################## | System information |[/b]

MB: Hewlett-Packard (167C) 
CPU: Intel(R) Pentium(R) CPU B940 @ 2.00GHz
RAM -> [Total : 3006 Mo | Free : 1984 Mo]
Bios: Hewlett-Packard
Boot: Normal boot

OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1
WB: Internet Explorer : 11.00.9600.16428
WB: Google Chrome : 43.0.2357.65

[b]################## | Security Information |[/b]

AV: avast! Antivirus [[b](!) Disabled[/b] |Updated]
AS: Windows Defender [Enabled |Updated]
AS: avast! Antivirus [[b](!) Disabled[/b] |Updated]
AS: Malwarebytes Anti-Malware : 2.1.6.1022
FW: Windows Firewall [Enabled]
SC: Security Center [Enabled]
WU: Windows Update [Enabled]

[b]################## | Disk Information |[/b]

C:\ (%SystemDrive%) -> Fixed disk # 276 Gb (59 Gb free - 21%) [] # NTFS
E:\ -> Fixed disk # 17 Gb (3 Gb free - 15%) [HP_RECOVERY] # NTFS
F:\ -> Fixed disk # 5 Gb (2 Gb free - 43%) [HP_TOOLS] # FAT32
J:\ -> Removable disk # 29 Gb (28 Gb free - 95%) [KINGSTON] # FAT32

[b]################## | Generic Research |[/b]


(!) Temporary files deleted. (9.24296188354492 MB)

[b]################## | Registry |[/b]


[b]################## | Regedit Run |[/b]

F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe,
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
04 - HKCU\..\Run : [cz.seznam.software.autoupdate] "C:\Users\Lucie\AppData\Roaming\Seznam.cz\szninstall.exe" -c
04 - HKCU\..\Run : [cz.seznam.software.szndesktop] "C:\Users\Lucie\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe"  -q
04 - HKCU\..\Run : [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
04 - HKCU\..\Run : [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
04 - HKLM\..\Run : [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
04 - HKLM\..\Run : [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
04 - HKLM\..\Run : [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
04 - HKLM\..\Run : [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\..\Run : [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
04 - HKLM\..\Run : [DTRun] c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
04 - HKLM\..\Run : [HPConnectionManager] c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
04 - HKLM\..\Run : [HPQuickWebProxy] "c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
04 - HKLM\..\Run : [SSBkgdUpdate] "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
04 - HKLM\..\Run : [OpwareSE4] "C:\Program Files (x86)\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
04 - HKLM\..\Run : [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
04 - HKLM\..\Run : [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\..\Run : [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\..\Run : [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - [x64] HKLM\..\Run : [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
04 - [x64] HKLM\..\Run : [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
04 - [x64] HKLM\..\Run : [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
04 - [x64] HKLM\..\Run : [IgfxTray] C:\windows\system32\igfxtray.exe
04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\windows\system32\hkcmd.exe
04 - [x64] HKLM\..\Run : [Persistence] C:\windows\system32\igfxpers.exe
04 - [x64] HKLM\..\Run : [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
04 - [x64] HKLM\..\Run : [MfeEpePcMonitor] "C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe"
04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-1277503925-3455442646-631812523-1001\..\Run : [cz.seznam.software.autoupdate] "C:\Users\Lucie\AppData\Roaming\Seznam.cz\szninstall.exe" -c
04 - HKU\S-1-5-21-1277503925-3455442646-631812523-1001\..\Run : [cz.seznam.software.szndesktop] "C:\Users\Lucie\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe"  -q
04 - HKU\S-1-5-21-1277503925-3455442646-631812523-1001\..\Run : [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
04 - HKU\S-1-5-21-1277503925-3455442646-631812523-1001\..\Run : [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe

[b]################## | UsbFix - Information |[/b]

Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]How to remove shortcut virus on flash disk (Video)[/url]
Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]Shortcut virus on flash disk, What is it ?[/url]

[b]################## | Hijack |[/b]


[b]################## | C:\ %SystemDrive% - Fixed drive (NTFS) |[/b]

[21/05/2015 - 06:29:53 | ASH | 3078520 Ko] - C:\hiberfil.sys
[21/05/2015 - 20:44:00 | ASH | 4723420 Ko] - C:\pagefile.sys
[17/08/2011 - 12:27:37 | D] - C:\SYSTEM.SAV
[17/08/2011 - 12:28:14 | SHD] - C:\$Recycle.Bin
[14/07/2009 - 03:38:58 | RASH | 375 Ko] - C:\bootmgr
[14/07/2009 - 05:20:08 | D] - C:\PerfLogs
[14/07/2009 - 07:08:56 | SHD] - C:\Documents and Settings
[27/07/2009 - 17:04:41 | SHD] - C:\boot
[10/05/2011 - 21:24:02 | D] - C:\EFI
[10/05/2011 - 22:29:07 | D] - C:\hp
[26/09/2011 - 17:40:50 | RHD] - C:\MSOCache
[11/05/2014 - 13:44:00 | D] - C:\30c40db4ce0d5827f6
[26/01/2015 - 18:02:24 | RD] - C:\Users
[20/02/2015 - 10:13:58 | D] - C:\Windows
[20/02/2015 - 12:00:49 | D] - C:\TMP
[17/03/2015 - 00:56:15 | HD] - C:\ProgramData
[24/03/2015 - 20:31:20 | D] - C:\Program Files
[02/04/2015 - 22:03:26 | D] - C:\swsetup
[23/04/2015 - 08:15:28 | D] - C:\JPGToPDF
[23/04/2015 - 08:20:15 | D] - C:\output
[19/05/2015 - 14:39:52 | D] - C:\Program Files (x86)
[21/05/2015 - 06:05:10 | SHD] - C:\System Volume Information
[21/05/2015 - 20:48:51 | D] - C:\UsbFix

[b]################## | E:\ - Fixed drive (NTFS) |[/b]

[19/01/2012 - 22:54:16 | A | 0 Ko] - E:\HPSF_Rep.txt
[31/05/2011 - 21:05:32 | D] - E:\system.sav
[15/09/2011 - 12:21:11 | A | 0 Ko] - E:\HP_WSD.dat
[17/08/2011 - 12:28:14 | SHD] - E:\$RECYCLE.BIN
[14/07/2009 - 03:38:58 | ASH | 375 Ko] - E:\bootmgr
[31/05/2011 - 21:05:31 | A | 0 Ko] - E:\HP_WINRE
[17/08/2011 - 12:15:13 | ASHD] - E:\Recovery
[17/08/2011 - 12:15:14 | ASHD] - E:\boot
[24/10/2011 - 09:13:08 | SHD] - E:\System Volume Information

[b]################## | F:\ - Fixed drive (FAT32) |[/b]

[19/01/2012 - 21:54:18 | A | 0 Ko] - F:\HPSF_Rep.txt
[15/09/2011 - 12:21:12 | A | 0 Ko] - F:\HP_WSD.dat
[31/05/2011 - 11:17:46 | SHD] - F:\$RECYCLE.BIN
[31/05/2011 - 11:03:28 | A | 0 Ko] - F:\HP_Tools
[13/09/2013 - 15:48:46 | AD] - F:\Hewlett-Packard

[b]################## | J:\ - Removable drive (FAT32) |[/b]

[21/05/2015 - 14:14:42 | D] - J:\dle

[b]################## | Vaccin |[/b]

C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
J:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

[b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] |[/b]
