Sei sulla pagina 1di 6

############################## | UsbFix V 7.

165 | [Research]
User: ash (Administrator) # ASH-PC
Updated 20/02/2014 by El Desaparecido - Team SosVirus
Started at 09:17:09 | 21/03/2014
Website : http://www.en.usbfix.net/
Changelog : http://www.en.usbfix.net/changelog/
Support : http://www.sosvirus.net/
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.en.usbfix.net/contact/
PC: SAMSUNG ELECTRONICS CO., LTD. (RV420/RV520/RV720/E3530/S3530)
CPU: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
RAM -> [Total : 4011 Mo| Free : 2080 Mo]
Bios: Phoenix Technologies Ltd.
Boot: Normal boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 9.0.8112.16421
WB: Google Chrome : 33.0.1750.154
SC:
WU:
AV:
AV:
AV:
AS:
AS:
AS:
AS:
FW:
FW:
AS:

Security Center [Enabled]


Windows Update [Enabled]
avast! Antivirus [Enabled | (!) Outdated]
Norton Internet Security [(!) Disabled | (!) Outdated]
AVG Anti-Virus Free Edition 2012 [Enabled | (!) Outdated]
avast! Antivirus [Enabled | (!) Outdated]
AVG Anti-Virus Free Edition 2012 [Enabled | (!) Outdated]
Windows Defender [(!) Disabled | Updated]
Norton Internet Security [(!) Disabled | (!) Outdated]
Norton Internet Security [(!) Disabled]
Windows FireWall [Enabled]
Malwarebytes' Anti-Malware : 1.75.0001

C:\
D:\
E:\
F:\
G:\

(%systemdrive%) -> Fixed drive # 231 Gb (55 Mb free - 24%) [] # NTFS


-> Fixed drive # 346 Gb (41 Mb free - 12%) [] # NTFS
-> CD-ROM
-> CD-ROM
-> Removable drive # 15 Gb (14 Mb free - 99%) [] # FAT32

################## | Active Processes |


C:\PROGRA~2\AVG\AVG2012\avgrsa.exe (ID: 632 |ParentID: 620)
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe (ID: 680 |ParentID: 632)
C:\windows\system32\csrss.exe (ID: 980 |ParentID: 952)
C:\windows\system32\wininit.exe (ID: 348 |ParentID: 952)
C:\windows\system32\csrss.exe (ID: 600 |ParentID: 360)
C:\windows\system32\services.exe (ID: 940 |ParentID: 348)
C:\windows\system32\winlogon.exe (ID: 964 |ParentID: 360)
C:\windows\system32\lsass.exe (ID: 988 |ParentID: 348)
C:\windows\system32\lsm.exe (ID: 1000 |ParentID: 348)
C:\windows\system32\svchost.exe (ID: 1072 |ParentID: 940)
C:\windows\system32\svchost.exe (ID: 1180 |ParentID: 940)
C:\windows\System32\svchost.exe (ID: 1284 |ParentID: 940)
C:\windows\System32\svchost.exe (ID: 1320 |ParentID: 940)
C:\windows\system32\svchost.exe (ID: 1348 |ParentID: 940)
C:\windows\system32\svchost.exe (ID: 1480 |ParentID: 940)
C:\windows\system32\svchost.exe (ID: 1560 |ParentID: 940)
C:\windows\system32\svchost.exe (ID: 1680 |ParentID: 940)

C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ID: 1744 |ParentID: 940)


C:\windows\system32\WLANExt.exe (ID: 1752 |ParentID: 1320)
C:\windows\system32\conhost.exe (ID: 1760 |ParentID: 980)
C:\windows\System32\spoolsv.exe (ID: 2004 |ParentID: 940)
C:\windows\system32\Dwm.exe (ID: 2016 |ParentID: 1320)
C:\windows\Explorer.EXE (ID: 992 |ParentID: 1936)
C:\windows\system32\svchost.exe (ID: 1580 |ParentID: 940)
C:\windows\system32\taskhost.exe (ID: 1912 |ParentID: 940)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1388 |ParentID
: 940)
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (ID: 2080 |ParentID:
940)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDevic
eService.exe (ID: 2108 |ParentID: 940)
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (ID: 2220 |ParentID: 940)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 2264 |ParentID: 940)
C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (ID:
2308 |ParentID: 940)
C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (ID: 2344 |Paren
tID: 940)
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (ID: 2452 |ParentID: 940)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID: 2504 |ParentID: 992)
C:\Program Files\Elantech\ETDCtrl.exe (ID: 2512 |ParentID: 992)
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (ID: 2612 |ParentID: 992)
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE (ID: 2636 |ParentID:
940)
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (ID: 2732 |ParentID: 940)
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (ID: 2800 |ParentID:
940)
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE (ID: 2884 |ParentID:
940)
C:\Program Files\Intel\WiFi\bin\EvtEng.exe (ID: 2936 |ParentID: 940)
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (
ID: 2956 |ParentID: 992)
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.ex
e (ID: 3016 |ParentID: 992)
C:\windows\system32\taskeng.exe (ID: 1876 |ParentID: 1348)
C:\windows\system32\taskeng.exe (ID: 2488 |ParentID: 1348)
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (ID: 2012 |ParentID: 940)
C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe (ID: 3192 |ParentID:
940)
C:\Program Files (x86)\Google\Drive\googledrivesync.exe (ID: 3200 |ParentID: 992
)
C:\Program Files (x86)\Skype\Phone\Skype.exe (ID: 3240 |ParentID: 992)
C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe (ID
: 3276 |ParentID: 940)
C:\Users\ash\AppData\Roaming\uTorrent\uTorrent.exe (ID: 3284 |ParentID: 992)
C:\Windows\System32\spool\drivers\x64\3\E_YATII2E.EXE (ID: 3328 |ParentID: 992)
C:\Program Files (x86)\EPSON\MyEpson Portal\mep.exe (ID: 3448 |ParentID: 3192)
C:\Program Files (x86)\LogicInMind\Logic Server\LogicServer.exe (ID: 3456 |Paren
tID: 992)
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (ID: 3492 |ParentID: 3360)
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (ID: 3544 |ParentID:
3360)
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (ID: 3672 |Parent
ID: 940)
C:\Program Files (x86)\AVG Secure Search\vprot.exe (ID: 3736 |ParentID: 3360)
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (ID: 3788 |ParentID:
940)
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe (ID: 3916 |ParentID: 2220)

C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ID: 3928 |Paren


tID: 940)
C:\Program Files\AVAST Software\Avast\AvastUI.exe (ID: 4040 |ParentID: 3360)
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe (ID: 4052 |ParentID: 2220)
C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (ID: 3120 |Pare
ntID: 2488)
C:\windows\splwow64.exe (ID: 3124 |ParentID: 3192)
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (ID: 3180 |ParentID: 1876)
C:\Program Files\SRS Labs\SRS Control Panel\srspanel_64.exe (ID: 2796 |ParentID:
1876)
C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe (ID: 3224 |P
arentID: 2488)
C:\windows\system32\svchost.exe (ID: 1432 |ParentID: 940)
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\Too
lbarUpdater.exe (ID: 3604 |ParentID: 940)
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (ID: 127
6 |ParentID: 3360)
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (ID: 4160
|ParentID: 3360)
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (ID: 4252 |ParentID: 3360)
C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe (ID: 4360 |ParentID: 940)
C:\Program Files (x86)\USB-AV Antivirus\usb-av.exe (ID: 4420 |ParentID: 3360)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 452
8 |ParentID: 940)
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\log
gingserver.exe (ID: 4560 |ParentID: 3604)
C:\windows\system32\conhost.exe (ID: 4568 |ParentID: 980)
C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe (ID
: 4788 |ParentID: 3276)
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (ID: 5004 |Paren
tID: 940)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 43
92 |ParentID: 4528)
C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe (ID: 2340 |ParentID: 940)
C:\windows\system32\wbem\unsecapp.exe (ID: 3420 |ParentID: 1072)
C:\windows\system32\EscSvc64.exe (ID: 3060 |ParentID: 940)
C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (ID: 4208 |ParentID: 940)
C:\windows\system32\wbem\wmiprvse.exe (ID: 5380 |ParentID: 1072)
C:\windows\system32\wbem\wmiprvse.exe (ID: 5388 |ParentID: 1072)
C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (ID: 5
460 |ParentID: 1072)
C:\windows\system32\igfxext.exe (ID: 6108 |ParentID: 1072)
C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (ID:
5524 |ParentID: 2488)
C:\Program Files (x86)\Google\Drive\googledrivesync.exe (ID: 4768 |ParentID: 320
0)
C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (ID: 4036 |ParentID
: 2488)
C:\windows\system32\igfxsrvc.exe (ID: 948 |ParentID: 1072)
C:\windows\system32\SearchIndexer.exe (ID: 2604 |ParentID: 940)
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe (ID: 4576 |ParentID: 2820
)
C:\windows\System32\alg.exe (ID: 1372 |ParentID: 940)
C:\windows\system32\svchost.exe (ID: 6272 |ParentID: 940)
C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (ID:
6572 |ParentID: 1876)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 6716 |ParentID: 940)
C:\Program Files\Elantech\ETDCtrlHelper.exe (ID: 6724 |ParentID: 2512)
C:\windows\System32\WUDFHost.exe (ID: 6864 |ParentID: 1320)
C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (ID: 6968 |Pa

rentID: 2488)
C:\windows\splwow64.exe (ID: 6488 |ParentID: 3448)
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (ID: 3524 |ParentID: 1892)
C:\windows\System32\svchost.exe (ID: 7424 |ParentID: 940)
C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (ID: 7492
|ParentID: 1892)
C:\windows\system32\hkcmd.exe (ID: 7580 |ParentID: 1892)
C:\windows\system32\igfxtray.exe (ID: 8004 |ParentID: 1892)
C:\windows\system32\DllHost.exe (ID: 6764 |ParentID: 1072)
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (ID: 3832 |Paren
tID: 1892)
C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe (ID: 5424 |
ParentID: 2488)
C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe (ID: 6472 |ParentID: 1892)
C:\windows\system32\igfxpers.exe (ID: 7576 |ParentID: 1892)
C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (ID: 65
60 |ParentID: 2488)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (
ID: 2152 |ParentID: 940)
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (ID: 1812 |Pa
rentID: 940)
C:\windows\system32\wbem\unsecapp.exe (ID: 6348 |ParentID: 1072)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (
ID: 7288 |ParentID: 940)
C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE (ID: 6624 |ParentID:
992)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\
OSPPSVC.EXE (ID: 5952 |ParentID: 940)
################## | Regedit Run |
04 - HKCU\..\Run : [EPSON Stylus T10 Series] C:\windows\system32\spool\DRIVERS\x
64\3\E_IATIEBS.EXE /FU "C:\windows\TEMP\E_SC2D3.tmp" /EF "HKCU"
04 - HKCU\..\Run : [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMesse
nger.exe" -quiet
04 - HKCU\..\Run : [EPSON L100 Series] C:\windows\system32\spool\DRIVERS\x64\3\E
_IATIGTP.EXE /FU "C:\windows\TEMP\E_S2941.tmp" /EF "HKCU"
04 - HKCU\..\Run : [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\I
nternet Services\ubd.exe
04 - HKCU\..\Run : [iCloudServices] C:\Program Files (x86)\Common Files\Apple\In
ternet Services\iCloudServices.exe
04 - HKCU\..\Run : [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple
\Internet Services\ApplePhotoStreams.exe
04 - HKCU\..\Run : [Facebook Update] "C:\Users\ash\AppData\Local\Facebook\Update
\FacebookUpdate.exe" /c /nocrashserver
04 - HKCU\..\Run : [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\google
drivesync.exe" /autostart
04 - HKCU\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minim
ized /regrun
04 - HKCU\..\Run : [EPLTarget\P0000000000000004] C:\windows\system32\spool\DRIVE
RS\x64\3\E_YATII2E.EXE /EPT "EPLTarget\P0000000000000004" /M "L210 Series"
04 - HKCU\..\Run : [AdobeBridge]
04 - HKCU\..\Run : [uTorrent] "C:\Users\ash\AppData\Roaming\uTorrent\uTorrent.ex
e" /MINIMIZED
04 - HKCU\..\Run : [EPLTarget\P0000000000000002] C:\windows\system32\spool\DRIVE
RS\x64\3\E_YATII2E.EXE /EPT "EPLTarget\P0000000000000002" /M "L210 Series" /EF "
HKCU"
04 - HKLM\..\Run : [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
04 - HKLM\..\Run : [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\re
alsched.exe" -osboot

04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.


0\AdobeARM.exe"
04 - HKLM\..\Run : [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\B
CSSync.exe" /DelayServices
04 - HKLM\..\Run : [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
04 - HKLM\..\Run : [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe
" -atboottime
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Jav
a\Java Update\jusched.exe"
04 - HKLM\..\Run : [NPSStartup]
04 - HKLM\..\Run : [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /
nogui
04 - HKLM\..\Run : [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple
Application Support\APSDaemon.exe"
04 - HKLM\..\Run : [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\Switc
hBoard\SwitchBoard.exe
04 - HKLM\..\Run : [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files
\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
04 - HKLM\..\Run : [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\
Updater\TBNotifier.exe"
04 - HKLM\..\Run : [EEventManager] "C:\Program Files (x86)\Epson Software\Event
Manager\EEventManager.exe"
04 - HKLM\..\Run : [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE startup
04 - HKLM\..\Run : [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
04 - HKLM\..\Run : [USB-AV-Antivirus] C:\Program Files (x86)\USB-AV Antivirus\us
b-av.exe
04 - HKLM64\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
-s
04 - HKLM64\..\Run : [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
04 - HKLM64\..\Run : [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.e
xe /logon
04 - HKLM64\..\Run : [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMe
nu\CNSLMAIN.exe /logon
04 - HKLM64\..\Run : [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\
Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe
/autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe
/autoRun
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [EPSON Stylus T1
0 Series] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEBS.EXE /FU "C:\windows\
TEMP\E_SC2D3.tmp" /EF "HKCU"
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [Messenger (Yaho
o!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [EPSON L100 Seri
es] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIGTP.EXE /FU "C:\windows\TEMP\E
_S2941.tmp" /EF "HKCU"
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [MobileDocuments
] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [iCloudServices]
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [ApplePhotoStrea
ms] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStream
s.exe
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [Facebook Update
] "C:\Users\ash\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashser
ver
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [GoogleDriveSync
] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart

04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [Skype] "C:\Prog


ram Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [EPLTarget\P0000
000000000004] C:\windows\system32\spool\DRIVERS\x64\3\E_YATII2E.EXE /EPT "EPLTar
get\P0000000000000004" /M "L210 Series"
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [AdobeBridge]
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [uTorrent] "C:\U
sers\ash\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKU\S-1-5-21-218970663-3732740050-1947231599-1000\..\Run : [EPLTarget\P0000
000000000002] C:\windows\system32\spool\DRIVERS\x64\3\E_YATII2E.EXE /EPT "EPLTar
get\P0000000000000002" /M "L210 Series" /EF "HKCU"
04 - HKU\S-1-5-18\..\Run : [EPLTarget\P0000000000000000] C:\windows\system32\spo
ol\DRIVERS\x64\3\E_YATII2E.EXE /EPT "EPLTarget\P0000000000000000" /M "L210 Serie
s"
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
################## | Generic Research |
################## | Registry |
################## | E.O.F | http://www.en.usbfix.net/ - http://www.sosvirus.net
|

Potrebbero piacerti anche