[b]############################## | UsbFix V 7.941 | [Research][/b] User: Lewy (Administrator) # LEWY-PC Updated 19/05/2015 by El Desaparecido - SosVirus Started at 19:51:46 | 19/05/2015 Website : [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] Changelog : [url=http://www.en.usbfix.net/changelog/]http://www.en.usbfix.net/changelog/[/url] Support : [url=http://www.sos-virus.net/]http://www.sos-virus.net/[/url] Live detection : [url=http://how-to-remove.us/]http://how-to-remove.us/[/url] Contact : [url=http://www.en.usbfix.net/contact/]http://www.en.usbfix.net/contact/[/url] [b]################## | System information |[/b] MB: LENOVO (Product Name) CPU: Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz GC: Intel(R) HD Graphics 4000 GC: NVIDIA GeForce GTX 660M RAM -> [Total : 3998 Mo | Free : 2639 Mo] Bios: LENOVO Boot: Normal boot OS: Microsoft™ Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1 WB: Internet Explorer : 11.00.9600.16428 WB: Mozilla Firefox : 37.0.2 [b]################## | Security Information |[/b] AS: Windows Defender [Enabled |[b](!) Outdated[/b]] FW: Windows Firewall [Enabled] SC: Security Center [Enabled] WU: Windows Update [Enabled] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Fixed disk # 100 Gb (48 Gb free - 48%) [] # NTFS D:\ -> Fixed disk # 830 Gb (62 Gb free - 8%) [] # NTFS G:\ -> Removable disk # 4 Gb (3 Gb free - 89%) [LEWY] # NTFS [b]################## | Autorun |[/b] G:\System Volume Information.lnk -> G:\home.vbe [b]################## | Startup |[/b] F2 - HKLM\..\Winlogon : [Shell] Explorer.exe F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe F2 - HKLM\..\Winlogon : [Userinit] userinit.exe, F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe, 04 - HKCU\..\Run : [home] wscript.exe //B "C:\Users\Lewy\AppData\Local\Temp\home.vbe" 04 - HKLM\..\Run : [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" 04 - HKLM\..\Run : [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery" 04 - HKLM\..\Run : [GamingMouse] C:\Program Files (x86)\GamingMouse\hid.exe 04 - [x64] HKLM\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s 04 - [x64] HKLM\..\Run : [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 04 - [x64] HKLM\..\Run : [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery" 04 - [x64] HKLM\..\Run : [IgfxTray] C:\Windows\system32\igfxtray.exe 04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\Windows\system32\hkcmd.exe 04 - [x64] HKLM\..\Run : [Persistence] C:\Windows\system32\igfxpers.exe 04 - [x64] HKLM\..\Run : [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe 04 - [x64] HKLM\..\Run : [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe 04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe 04 - [x64] HKLM\..\Run : [SynLenovoGestureMgr] %ProgramFiles%\Synaptics\SynTP\SynLenovoGestureMgr.exe 04 - [x64] HKLM\..\Run : [home] wscript.exe //B "C:\Users\Lewy\AppData\Local\Temp\home.vbe" 04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-21-1332373539-1881414760-2737133929-1000\..\Run : [home] wscript.exe //B "C:\Users\Lewy\AppData\Local\Temp\home.vbe" 04 - HKU\S-1-5-21-1332373539-1881414760-2737133929-1001\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-21-1332373539-1881414760-2737133929-1001\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04GS - rvlkl.lnk : C:\ProgramData\rvlkl\rvlkl.exe [b]################## | Generic Research |[/b] Found! C:\Users\Lewy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\home.vbe Found! C:\Users\Lewy\AppData\Local\Temp\home.vbe Found! G:\home.vbe Found! G:\System Volume Information.lnk [b]################## | Registry |[/b] Found! [x64] HKLM\Software\Microsoft\Windows\CurrentVersion\Run|home Found! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|home Found! HKU\S-1-5-21-1332373539-1881414760-2737133929-1000\Software\Microsoft\Windows\CurrentVersion\Run|home Found! HKCU|di [b]################## | UsbFix - Information |[/b] Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]How to remove shortcut virus on flash disk (Video)[/url] Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]Shortcut virus on flash disk, What is it ?[/url] Live detection : [url=http://how-to-remove.us/]http://how-to-remove.us/[/url] [b]################## | Attrib - Restore |[/b] [b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] |[/b]