Você está na página 1de 3

# ----------------------------------------------------

# UsbFix Antivirus Free


# ----------------------------------------------------
# Version : 11.014
# Database : 2019.03.26
# Contact : https://www.usb-antivirus.com/contact
# ----------------------------------------------------
# Scan type : USB
# User : hp (Administrator)
# Device : HP-PC
# Started : 12/05/2019 10:28:37
# ----------------------------------------------------

------------ | Analyzed disks |

H:\ NTFS (14GB/14GB) [Removable]

------------ | Infected elements |

~ No element detected ~

------------ | Run |

F2 - HKLM\..\Winlogon : [Shell] explorer.exe


F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe
04 - HKCU\..\Run : [Avro Keyboard] D:\Avro Keyboard\Avro Keyboard.exe
04 - HKCU\..\Run : [uTorrent]
"C:\Users\hp\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKCU\..\Run : [IDMan] C:\Program Files (x86)\Internet Download
Manager\IDMan.exe /onboot
04 - HKCU\..\Run : [BingSvc]
C:\Users\hp\AppData\Local\Microsoft\BingSvc\BingSvc.exe
04 - HKCU\..\Run : [OneDrive]
"C:\Users\hp\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
04 - HKCU\..\RunOnce : [Application Restart #0]
D:\UCBrowser\Application\UCBrowser.exe --flag-switches-begin --flag-switches-end
--wow-extension-center-url=https://chrome.google.com/webstore/category/extensions
--restore-last-session --flag-switches-begin --flag-switches-end --wow-extension-
center-url=https://chrome.google.com/webstore/category/extensions
04 - HKCU\..\RunOnce : [Delete Cached Update Binary] C:\WINDOWS\system32\cmd.exe /q
/c del /q "C:\Users\hp\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
04 - HKCU\..\RunOnce : [Delete Cached Standalone Update Binary]
C:\WINDOWS\system32\cmd.exe /q /c del /q
"C:\Users\hp\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
04 - HKCU\..\RunOnce : [Uninstall 19.043.0304.0007\amd64]
C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q
"C:\Users\hp\AppData\Local\Microsoft\OneDrive\19.043.0304.0007\amd64"
04 - HKCU\..\RunOnce : [Uninstall 19.043.0304.0007] C:\WINDOWS\system32\cmd.exe
/q /c rmdir /s /q "C:\Users\hp\AppData\Local\Microsoft\OneDrive\19.043.0304.0007"
04 - HKLM\..\Run : [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP Hotkey
Support\QLBController.exe
04 - HKLM\..\Run : [YouCam Service7] "C:\Program Files
(x86)\CyberLink\YouCam7\YouCamService7.exe" /s
04 - HKLM\..\Run : [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe"
/systemstartup
04 - [x64] HKLM\..\Run : [SecurityHealth] %ProgramFiles%\Windows
Defender\MSASCuiL.exe
04 - [x64] HKLM\..\Run : [RTHDVCPL] "C:\Program
Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
04 - [x64] HKLM\..\Run : [RtsCM] RTSCM64.EXE
04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
04 - HKU\S-1-5-19\..\Run : [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe
/thfirstsetup
04 - HKU\S-1-5-20\..\Run : [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe
/thfirstsetup
04 - HKU\S-1-5-21-3813432606-1499187374-2204906005-1003\..\Run : [Avro Keyboard]
D:\Avro Keyboard\Avro Keyboard.exe
04 - HKU\S-1-5-21-3813432606-1499187374-2204906005-1003\..\Run : [uTorrent]
"C:\Users\hp\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKU\S-1-5-21-3813432606-1499187374-2204906005-1003\..\Run : [IDMan] C:\Program
Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-21-3813432606-1499187374-2204906005-1003\..\Run : [BingSvc]
C:\Users\hp\AppData\Local\Microsoft\BingSvc\BingSvc.exe
04 - HKU\S-1-5-21-3813432606-1499187374-2204906005-1003\..\Run : [OneDrive]
"C:\Users\hp\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
04 - HKU\S-1-5-19\..\RunOnce : [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe
/Upgrade
04 - HKU\S-1-5-20\..\RunOnce : [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe
/Upgrade
04 - HKU\S-1-5-21-3813432606-1499187374-2204906005-1003\..\RunOnce : [Application
Restart #0] D:\UCBrowser\Application\UCBrowser.exe --flag-switches-begin --flag-
switches-end --wow-extension-center-
url=https://chrome.google.com/webstore/category/extensions --restore-last-session
--flag-switches-begin --flag-switches-end --wow-extension-center-
url=https://chrome.google.com/webstore/category/extensions
04 - HKU\S-1-5-21-3813432606-1499187374-2204906005-1003\..\RunOnce : [Delete Cached
Update Binary] C:\WINDOWS\system32\cmd.exe /q /c del /q
"C:\Users\hp\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
04 - HKU\S-1-5-21-3813432606-1499187374-2204906005-1003\..\RunOnce : [Delete Cached
Standalone Update Binary] C:\WINDOWS\system32\cmd.exe /q /c del /q
"C:\Users\hp\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
04 - HKU\S-1-5-21-3813432606-1499187374-2204906005-1003\..\RunOnce : [Uninstall
19.043.0304.0007\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q
"C:\Users\hp\AppData\Local\Microsoft\OneDrive\19.043.0304.0007\amd64"
04 - HKU\S-1-5-21-3813432606-1499187374-2204906005-1003\..\RunOnce : [Uninstall
19.043.0304.0007] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q
"C:\Users\hp\AppData\Local\Microsoft\OneDrive\19.043.0304.0007"

------------ | Tasks |

Task - DropboxUpdateTaskMachineCore --> C:\Program Files


(x86)\Dropbox\Update\DropboxUpdate.exe /c
Task - DropboxUpdateTaskMachineUA --> C:\Program Files
(x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
Task - FileAdvisorUpdate --> "C:\Program Files (x86)\File Type
Advisor\fileadvisor.exe" /updateprogram
Task - OneDrive Standalone Update Task-S-1-5-21-3813432606-1499187374-2204906005-
1003 --> %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task - Optimize Start Menu Cache Files-S-1-5-21-3813432606-1499187374-2204906005-
1001
Task - Optimize Start Menu Cache Files-S-1-5-21-3813432606-1499187374-2204906005-
1003
Task - Skype --> C:\Users\hp\AppData\Roaming\CRM INAANI rate Egypt Afghanistan BD
PAK NON CLI Route.wSf
Task - UCBrowserUpdater --> D:\UCBrowser\Application\update_task.exe /update
Task - UCBrowserUpdaterCore --> D:\UCBrowser\Application\update_task.exe /task=1
Task - User_Feed_Synchronization-{0AE6492C-126D-462A-84D3-5B8D9EC611CD} -->
C:\Windows\system32\msfeedssync.exe sync
Task - {65538412-036E-EF5D-B8D2-5C36965CC777} -->
C:\WINDOWS\system32\regsvr32.exe /s /n /i:"/rt" "C:\PROGRA~3\8633723d\e71f8226.dll"
Task - {C519A4BE-D415-44F4-A2AD-09EC391510E8} --> C:\Windows\system32\pcalua.exe -a
"J:\hp 450 G2\Keyboard, Mouse and Input Devices.exe" -d "J:\hp 450 G2"
Task - {C5391F45-E66F-470D-A360-FF6E1C9CD8BF} --> C:\WINDOWS\system32\pcalua.exe -a
"C:\Program Files (x86)\simplitec\KMPFaster\unins000.exe"
Task - {FBAFFC50-AC23-4A0A-B68B-1858726DEEF5} --> "c:\program files
(x86)\google\chrome\application\chrome.exe"
http://ui.skype.com/ui/0/7.0.0.102/en/go/help.faq.installer?LastError=1618

------------ | H:\ - Removable drive (NTFS) |

[16/11/2018 - 20:19:41 | A | 31 Ko] - AdmitCard_CSKUVPQV.pdf


[17/11/2018 - 09:17:48 | A | 31 Ko] - AdmitCard_CSMJHRUC.pdf
[30/04/2019 - 08:06:19 | A | 30 Ko] - tawhid.pdf

Infected elements : 0
Analyzed elements : 52555 in 00h 00m 04s

# UsbFix-Report-03.txt [7224B]

------------ | E.O.F |

Você também pode gostar