[b]############################## | UsbFix V 9.027 | [Clean][/b] User: Tomasz (Administrator) # TOMASZ-KOMP Updated 15/02/2017 by SOSVirus Started at 15:32:32 | 20/02/2017 Website : [url=https://www.usb-antivirus.com/]https://www.usb-antivirus.com/[/url] Tutorial : [url=https://www.usb-antivirus.com/tutorial/]https://www.usb-antivirus.com/tutorial/[/url] Support : [url=https://www.sosvirus.org/]https://www.sosvirus.org/[/url] Live detection : [url=http://www.sosmalware.com/usbfix/]http://www.sosmalware.com/usbfix/[/url] Contact : [url=https://www.usb-antivirus.com/contact/]https://www.usb-antivirus.com/contact/[/url] [b]################## | System information |[/b] MB: ASUSTeK COMPUTER INC. (B85-PLUS) CPU: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz GC: AMD Radeon R9 200 Series RAM -> [Total : 8098 Mo | Free : 4130 Mo] Bios: American Megatrends Inc. Boot: Normal boot OS: Microsoft™ Windows 10 Pro (6.3.14393 64-Bit) WB: Internet Explorer : 11.00.14393.0 WB: Microsoft Edge : 11.00.14393.693 (rs1_release.161220-1747) WB: Google Chrome : 56.0.2924.87 WB: Mozilla Firefox : 47.0 WB: Opera : 39.0.2256.71 [b]################## | Security Information |[/b] AV: Windows Defender [Enabled |Updated] AS: Windows Defender [Enabled |Updated] AS: Malwarebytes Anti-Malware : 2.2.0.1024 FW: Windows Firewall [Enabled] SC: Security Center [Enabled] WU: Windows Update [Enabled] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Fixed disk # 465 Gb (79 Gb free - 17%) [] # NTFS D:\ -> Removable disk # 14 Gb (14 Gb free - 100%) [USB DISK] # FAT32 [b]################## | Generic Research |[/b] Deleted! [x64] HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Start WingMan Profiler Restored! [D] D:\  Restored! D:\ \_-__-_--_--_-__-_--_--_--_-__-__-_--__-_--__---.{598F587C-1B3E-4E09-9AEE-B967963F8CEC} -> D:\_-__-_--_--_-__-_--_--_--_-__-__-_--__-_--__---.{598F587C-1B3E-4E09-9AEE-B967963F8CEC} Restored! D:\ \desktop.ini -> D:\desktop.ini Restored! D:\ \IndexerVolumeGuid -> D:\IndexerVolumeGuid [b]################## | Startup |[/b] F2 - HKLM\..\Winlogon : [Shell] explorer.exe F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe, 04 - HKCU\..\Run : [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart 04 - HKCU\..\Run : [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun 04 - HKCU\..\Run : [GG] "C:\Users\Tomasz\AppData\Local\GG\Application\gghub.exe" 04 - HKCU\..\Run : [Spotify Web Helper] "C:\Users\Tomasz\AppData\Roaming\Spotify\SpotifyWebHelper.exe" 04 - HKCU\..\Run : [SpyShelter] C:\Program Files (x86)\SpyShelter Premium\SpyShelter.exe 04 - HKCU\..\Run : [Spotify] "C:\Users\Tomasz\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized 04 - HKCU\..\Run : [vibranceGUI] "C:\Users\Tomasz\Desktop\xxx\vibranceGUI\vibrance.GUI.exe" -minimized 04 - HKCU\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun 04 - HKCU\..\Run : [Overwolf] "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent 04 - HKCU\..\Run : [IPLA!] C:\Program Files (x86)\ipla\ipla.exe /autorun 04 - HKCU\..\Run : [VeraCrypt] "C:\Program Files\VeraCrypt\VeraCrypt.exe" /q preferences /a logon 04 - HKCU\..\Run : [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR 04 - HKCU\..\Run : [OneDrive] "C:\Users\Tomasz\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background 04 - HKLM\..\Run : [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" 04 - HKLM\..\Run : [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe 04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 04 - [x64] HKLM\..\Run : [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s 04 - [x64] HKLM\..\Run : [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" 04 - [x64] HKLM\..\Run : [StartCN] "C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon 04 - [x64] HKLM\..\Run : [WindowsDefender] "%ProgramFiles%\Windows Defender\MSASCuiL.exe" 04 - HKU\S-1-5-19\..\Run : [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup 04 - HKU\S-1-5-20\..\Run : [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [GG] "C:\Users\Tomasz\AppData\Local\GG\Application\gghub.exe" 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [Spotify Web Helper] "C:\Users\Tomasz\AppData\Roaming\Spotify\SpotifyWebHelper.exe" 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [SpyShelter] C:\Program Files (x86)\SpyShelter Premium\SpyShelter.exe 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [Spotify] "C:\Users\Tomasz\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [vibranceGUI] "C:\Users\Tomasz\Desktop\xxx\vibranceGUI\vibrance.GUI.exe" -minimized 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [Overwolf] "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [IPLA!] C:\Program Files (x86)\ipla\ipla.exe /autorun 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [VeraCrypt] "C:\Program Files\VeraCrypt\VeraCrypt.exe" /q preferences /a logon 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR 04 - HKU\S-1-5-21-2831190625-1651721554-443938107-1001\..\Run : [OneDrive] "C:\Users\Tomasz\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background 04GS - XenoSuite.lnk : C:\Program Files (x86)\XenoBot\XenoSuite.exe 04GS - HDDHealth.lnk : C:\Program Files (x86)\HDD Health\hddhealth.exe [b]################## | C:\ %SystemDrive% - Fixed drive (NTFS) |[/b] [07/11/2007 - 07:00:40 | A | 17 Ko] - C:\eula.1040.txt [07/11/2007 - 07:00:40 | A | 17 Ko] - C:\eula.3082.txt [07/11/2007 - 07:00:40 | A | 17 Ko] - C:\eula.2052.txt [07/11/2007 - 07:00:40 | A | 17 Ko] - C:\eula.1042.txt [07/11/2007 - 07:00:40 | A | 0 Ko] - C:\eula.1041.txt [07/11/2007 - 07:00:40 | A | 17 Ko] - C:\eula.1036.txt [07/11/2007 - 07:00:40 | A | 10 Ko] - C:\eula.1033.txt [07/11/2007 - 07:00:40 | A | 17 Ko] - C:\eula.1031.txt [07/11/2007 - 07:00:40 | A | 17 Ko] - C:\eula.1028.txt [20/02/2017 - 13:25:04 | ASH | 1310720 Ko] - C:\pagefile.sys [20/02/2017 - 13:25:04 | ASH | 262144 Ko] - C:\swapfile.sys [07/11/2007 - 07:12:28 | A | 228 Ko] - C:\VC_RED.MSI [20/02/2017 - 15:08:38 | D] - C:\Config.Msi [07/11/2007 - 07:00:40 | A | 1 Ko] - C:\install.ini [07/11/2007 - 07:00:40 | A | 1 Ko] - C:\globdata.ini [02/11/2015 - 11:28:48 | A | 0 Ko] - C:\ftconfig.ini [07/11/2007 - 07:03:18 | A | 550 Ko] - C:\install.exe [07/11/2007 - 07:03:18 | A | 89 Ko] - C:\install.res.1033.dll [07/11/2007 - 07:03:18 | A | 93 Ko] - C:\install.res.1040.dll [07/11/2007 - 07:03:18 | A | 74 Ko] - C:\install.res.2052.dll [07/11/2007 - 07:03:18 | A | 78 Ko] - C:\install.res.1042.dll [07/11/2007 - 07:03:18 | A | 80 Ko] - C:\install.res.1041.dll [07/11/2007 - 07:03:18 | A | 95 Ko] - C:\install.res.1036.dll [07/11/2007 - 07:03:18 | A | 75 Ko] - C:\install.res.1028.dll [07/11/2007 - 07:03:18 | A | 94 Ko] - C:\install.res.3082.dll [07/11/2007 - 07:03:18 | A | 94 Ko] - C:\install.res.1031.dll [07/11/2007 - 07:09:22 | A | 1409 Ko] - C:\VC_RED.cab [07/11/2007 - 07:00:40 | A | 6 Ko] - C:\vcredist.bmp [29/12/2014 - 07:11:09 | SHD] - C:\$Recycle.Bin [28/01/2016 - 15:11:23 | SHD] - C:\found.000 [18/06/2013 - 13:18:29 | N | 0 Ko] - C:\BOOTNXT [22/08/2013 - 15:45:52 | SHD] - C:\Documents and Settings [18/03/2014 - 11:00:16 | RASH | 389 Ko] - C:\bootmgr [09/12/2014 - 02:06:42 | D] - C:\Intel [09/12/2014 - 19:56:43 | D] - C:\Riot Games [15/12/2014 - 16:10:32 | RHD] - C:\MSOCache [22/03/2015 - 13:47:36 | D] - C:\482e26e88b40594e9e [23/05/2015 - 18:47:30 | D] - C:\GOG Games [08/07/2015 - 19:15:42 | AD] - C:\WebServ [16/07/2016 - 12:47:47 | D] - C:\PerfLogs [03/08/2016 - 17:05:58 | D] - C:\xampp [13/08/2016 - 18:29:28 | D] - C:\AdwCleaner [08/10/2016 - 13:47:05 | RD] - C:\Users [08/10/2016 - 14:06:47 | SHD] - C:\Recovery [08/10/2016 - 14:08:10 | D] - C:\$GetCurrent [08/10/2016 - 14:10:04 | D] - C:\Windows10Upgrade [03/01/2017 - 15:52:20 | A | 0 Ko] - C:\END [26/01/2017 - 16:47:07 | D] - C:\AMD [27/01/2017 - 15:30:13 | RD] - C:\Program Files [29/01/2017 - 13:23:00 | D] - C:\KateBot [20/02/2017 - 14:42:56 | D] - C:\Windows [20/02/2017 - 14:46:04 | D] - C:\FRST [20/02/2017 - 15:07:58 | HD] - C:\ProgramData [20/02/2017 - 15:25:14 | RD] - C:\Program Files (x86) [20/02/2017 - 15:31:51 | D] - C:\UsbFix [b]################## | D:\ - Removable drive (FAT32) |[/b] [20/02/2017 - 11:19:56 | D] - D:\  [20/02/2017 - 12:43:12 | N | 7855 Ko] - D:\_-__-_--_--_-__-_--_--_--_-__-__-_--__-_--__---.{598F587C-1B3E-4E09-9AEE-B967963F8CEC} [20/02/2017 - 12:43:12 | N | 0 Ko] - D:\desktop.ini [20/02/2017 - 12:43:12 | N | 473 Ko] - D:\IndexerVolumeGuid [b]Analysed in 10.78 seconds[/b] [b]################## | E.O.F | [url=https://www.sosvirus.net/]https://www.sosvirus.net/[/url] | [url=https://www.usb-antivirus.com/]https://www.usb-antivirus.com/[/url] |[/b]