[b]############################## | UsbFix V 9.049 | [Research][/b] User: Grzesiek (Administrator) # GRZESIEK-HP Updated 27/05/2017 by SOSVirus Started at 09:48:45 | 30/05/2017 Website : [url=https://www.usb-antivirus.com/]https://www.usb-antivirus.com/[/url] Tutorial : [url=https://www.usb-antivirus.com/tutorial/]https://www.usb-antivirus.com/tutorial/[/url] Support : [url=https://www.sosvirus.net/en/]https://www.sosvirus.net/en/[/url] Live detection : [url=https://www.usbfix.net/]https://www.usbfix.net/[/url] Contact : [url=https://www.usb-antivirus.com/contact/]https://www.usb-antivirus.com/contact/[/url] [b]################## | System information |[/b] MB: ECS (Nettle3) CPU: AMD Phenom(tm) 9550 Quad-Core Processor RAM -> [Total : 8190 Mo | Free : 6307 Mo] Bios: Phoenix Technologies, LTD Boot: Normal boot OS: Microsoft™ Windows 7 Professional (6.1.7601 64-Bit) Service Pack 1 WB: Internet Explorer : 11.00.9600.16428 WB: Google Chrome : 58.0.3029.110 [b]################## | Security Information |[/b] AS: Windows Defender [Enabled |Updated] FW: Windows Firewall [Enabled] SC: Security Center [Enabled] WU: Windows Update [Enabled] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Fixed disk # 397 Gb (178 Gb free - 45%) [WIN 7] # NTFS D:\ -> Fixed disk # 401 Gb (274 Gb free - 68%) [HP] # NTFS E:\ -> Fixed disk # 500 Gb (191 Gb free - 38%) [PROJEKTY] # NTFS F:\ -> Fixed disk # 187 Gb (42 Gb free - 22%) [Nowy] # NTFS G:\ -> Fixed disk # 8 Gb (1 Gb free - 13%) [FACTORY_IMAGE] # NTFS H:\ -> Fixed disk # 500 Gb (56 Gb free - 11%) [FILMY] # NTFS J:\ -> Removable disk # 4 Gb (2 Gb free - 64%) [] # FAT32 [b]################## | Startup |[/b] F2 - HKLM\..\Winlogon : [Shell] explorer.exe F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe F2 - HKLM\..\Winlogon : [Userinit] userinit.exe F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe, 04 - HKCU\..\Run : [System Network Service] C:\Users\Grzesiek\AppData\Roaming\System32\svchost.exe 04 - HKCU\..\Run : [OneDrive] "C:\Users\Grzesiek\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background 04 - HKCU\..\Run : [Akamai NetSession Interface] "C:\Users\Grzesiek\AppData\Local\Akamai\netsession_win.exe" 04 - HKCU\..\Run : [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe 04 - HKLM\..\Run : [Onet.pl AutoUpdate] "C:\Program Files (x86)\Common Files\Onet.pl\NewAutoUpdate.exe" /updateexe 04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 04 - HKLM\..\Run : [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" 04 - HKLM\..\Run : [Autodesk Desktop App] "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray 04 - [x64] HKLM\..\Run : [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming 04 - [x64] HKLM\..\Run : [Bluetooth Connection Assistant] LBTWIZ.EXE -silent 04 - [x64] HKLM\..\Run : [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" 04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-21-3778464907-1183566303-1077457656-1001\..\Run : [System Network Service] C:\Users\Grzesiek\AppData\Roaming\System32\svchost.exe 04 - HKU\S-1-5-21-3778464907-1183566303-1077457656-1001\..\Run : [OneDrive] "C:\Users\Grzesiek\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background 04 - HKU\S-1-5-21-3778464907-1183566303-1077457656-1001\..\Run : [Akamai NetSession Interface] "C:\Users\Grzesiek\AppData\Local\Akamai\netsession_win.exe" 04 - HKU\S-1-5-21-3778464907-1183566303-1077457656-1001\..\Run : [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe 04 - HKU\S-1-5-18\..\Run : [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe 04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04GS - OneDrive dla firm.lnk : C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVE.EXE 04GS - Wysyłanie do programu OneNote.lnk : C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE 04GS - Windchill ProductPoint Client Manager.lnk : C:\Windows\Installer\{129024FF-A6C9-4696-91BC-570C6C05193A}\_F5BCEE176F60B4DABC6DF8.exe [b]################## | Generic Research |[/b] Found! C:\Users\Grzesiek\AppData\Roaming\System32\svchost.exe Found! J:\System Volume Information.exe Found! C:\Users\Grzesiek\AppData\Roaming\System32\minerd.exe Found! C:\Users\Grzesiek\AppData\Roaming\System32\libcurl-4.dll Found! C:\Users\Grzesiek\AppData\Roaming\System32\minerd.exe Found! C:\Users\Grzesiek\AppData\Roaming\System32\pthreadGC2.dll Found! C:\Users\Grzesiek\AppData\Roaming\System32\svchost.exe Found! C:\Users\Grzesiek\AppData\Roaming\System32\System.ini Found! C:\Users\Grzesiek\AppData\Roaming\System32 Found! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|System Network Service Found! HKU\S-1-5-21-3778464907-1183566303-1077457656-1001\Software\Microsoft\Windows\CurrentVersion\Run|System Network Service [b]Analysed in 634.2 seconds[/b] [b]################## | E.O.F | [url=https://www.sosvirus.net/]https://www.sosvirus.net/[/url] | [url=https://www.usb-antivirus.com/]https://www.usb-antivirus.com/[/url] |[/b]