popravdě nejsem si jistý...
############################## | UsbFix V 7.181 | [Research]
User: uzivatel (Administrator) # UZIVATEL-HP
Updated 31/08/2014 by El Desaparecido - SosVirus
Started at 18:14:41 | 21/12/2014
Website :
http://www.en.usbfix.net/
Changelog :
http://www.en.usbfix.net/changelog/
Support :
http://www.sosvirus.net/
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.en.usbfix.net/contact/
################## | System information |
MB: Hewlett-Packard (1475)
CPU: AMD Turion(tm) II P520 Dual-Core Processor
RAM -> [Total : 2810 Mo | Free : 843 Mo]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft™ Windows 7 Home Premium (6.1.7601 32-Bit) Service Pack 1
WB: Internet Explorer : 11.00.9600.16428
################## | Security Information |
AV: Avira Desktop [Enabled |Updated]
AV: ZoneAlarm Free Firewall Antivirus [Enabled |Updated]
AS: Avira Desktop [Enabled |Updated]
AS: Windows Defender [Enabled |Updated]
AS: ZoneAlarm Free Firewall Anti-Spyware [Enabled |Updated]
FW: ZoneAlarm Free Firewall Firewall [Enabled]
FW: Windows Firewall [
(!) Disabled]
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
################## | Disk Information |
C:\ (%SystemDrive%) -> Fixed disk # 466 Gb (30 Gb free - 7%) [] # NTFS
E:\ -> CD-ROM # 1 Mb (0 Mb free - 0%) [HP Launcher] # CDFS
F:\ -> Fixed disk # 931 Gb (249 Gb free - 27%) [HP SimpleSave] # NTFS
G:\ -> Removable disk # 62 Mb (0 Mb free - 0%) [] # FAT
################## | Regedit Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] C:\Windows\System32\Userinit.exe,
04 - HKCU\..\Run : [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
04 - HKCU\..\Run : [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
04 - HKCU\..\Run : [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
04 - HKCU\..\Run : [Google Update] "C:\Users\uzivatel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
04 - HKLM\..\Run : [QLBController] C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
04 - HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
04 - HKLM\..\Run : [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
04 - HKLM\..\Run : [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\..\Run : [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
04 - HKLM\..\Run : [ZoneAlarm] "C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe"
04 - HKLM\..\Run : [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
04 - HKLM\..\Run : [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
04 - HKLM\..\Run : [Broadcom Wireless Manager UI] C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe
04 - HKLM\..\Run : [Avira Systray] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
04 - HKLM\..\RunOnce : [NCPluginUpdater] "C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
04 - HKU\S-1-5-21-1949562949-18675200-2126537319-1001\..\Run : [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
04 - HKU\S-1-5-21-1949562949-18675200-2126537319-1001\..\Run : [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
04 - HKU\S-1-5-21-1949562949-18675200-2126537319-1001\..\Run : [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
04 - HKU\S-1-5-21-1949562949-18675200-2126537319-1001\..\Run : [Google Update] "C:\Users\uzivatel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
################## | Generic Research |
################## | Registry |
Found! HKCU\Software\OneKit
Found! HKU\S-1-5-21-1949562949-18675200-2126537319-1001\Software\OneKit
################## | UsbFix - Information |
Info :
How to remove shortcut virus on flash disk (Video)
Info :
Shortcut virus on flash disk, What is it ?
################## | Hijack |
Hijacked! [AH] G:\.HPIMAGE.VFS
################## | E.O.F | http://www.sosvirus.net/ | http://www.en.usbfix.net/ |