#   ----------------------------------------------------
#   UsbFix Antivirus Premium
#   ----------------------------------------------------
#   Version : 11.032
#   Database :
#   Contact : https://www.usb-antivirus.com/contact
#   ----------------------------------------------------
#   Scan type : Windows [Auto Scan]
#   User : King Technology (Administrator)
#   Device : DESKTOP-E9GF4RL
#   Started : 10/03/2023 11:30:22
#   ----------------------------------------------------
------------ | Analyzed disks |
C:\    NTFS   (41GB/232GB)      [Fixed]
D:\    NTFS   (143GB/146GB)     [Fixed]
E:\    NTFS   (128GB/222GB)     [Fixed]
I:\    NTFS   (98GB/98GB) [Fixed]
------------ | Infected elements |
~ No element detected ~
------------ | Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [OneDrive] "C:\Program Files\Microsoft OneDrive\OneDrive.exe"
/background
04 - HKCU\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\
IDMan.exe /onboot
04 - HKCU\..\Run : [com.squirrel.Teams.Teams] C:\Users\King Technology\AppData\
Local\Microsoft\Teams\Update.exe --processStart "Teams.exe" --process-start-args
"--system-initiated"
04 - HKCU\..\Run : [Skype for Desktop] C:\Program Files (x86)\Microsoft\Skype for
Desktop\Skype.exe
04 - HKCU\..\Run : [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
04 - HKCU\..\Run : [WallpaperEngine] "C:\Program Files (x86)\Steam\steamapps\
common\wallpaper_engine\wallpaper32.exe" -silent
04 - HKCU\..\Run : [com.blitz.app] "C:\Users\King Technology\AppData\Local\
Programs\Blitz\Blitz.exe" --autostart
04 - HKCU\..\Run : [ut] "C:\Users\King Technology\AppData\Roaming\utorrent\updates\
utorrent.exe" /MINIMIZED
04 - HKCU\..\Run : [Discord] "C:\Users\King Technology\AppData\Local\Discord\
Update.exe" --processStart Discord.exe
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\
Java Update\jusched.exe"
04 - HKLM\..\Run : [TeamsMachineInstaller] %ProgramFiles%\Teams Installer\Teams.exe
--checkInstall --source=PROPLUS
04 - [x64] HKLM\..\Run : [SecurityHealth] %windir%\system32\
SecurityHealthSystray.exe
04 - [x64] HKLM\..\Run : [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\
RtkNGUI64.exe" -s
04 - [x64] HKLM\..\Run : [RtHDVBg_PushButton] "C:\Program Files\Realtek\Audio\HDA\
RAVBg64.exe" /IM
04 - [x64] HKLM\..\Run : [egui] "C:\Program Files\ESET\ESET Antivirus\egui.exe"
/hide /waitservice
04 - [x64] HKLM\..\Run : [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common
Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
04 - [x64] HKLM\..\Run : [AdobeGCInvoker-1.0] "C:\Program Files (x86)\Common Files\
Adobe\AdobeGCClient\AGCInvokerUtility.exe"
04 - HKU\S-1-5-19\..\Run : [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe
/thfirstsetup
04 - HKU\S-1-5-20\..\Run : [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe
/thfirstsetup
04 - HKU\S-1-5-21-3516208702-2551172651-115148956-1002\..\Run : [OneDrive] "C:\
Program Files\Microsoft OneDrive\OneDrive.exe" /background
04 - HKU\S-1-5-21-3516208702-2551172651-115148956-1002\..\Run : [IDMan] C:\Program
Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-21-3516208702-2551172651-115148956-1002\..\Run :
[com.squirrel.Teams.Teams] C:\Users\King Technology\AppData\Local\Microsoft\Teams\
Update.exe --processStart "Teams.exe" --process-start-args "--system-initiated"
04 - HKU\S-1-5-21-3516208702-2551172651-115148956-1002\..\Run : [Skype for Desktop]
C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
04 - HKU\S-1-5-21-3516208702-2551172651-115148956-1002\..\Run : [Steam] "C:\Program
Files (x86)\Steam\steam.exe" -silent
04 - HKU\S-1-5-21-3516208702-2551172651-115148956-1002\..\Run : [WallpaperEngine]
"C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe" -
silent
04 - HKU\S-1-5-21-3516208702-2551172651-115148956-1002\..\Run : [com.blitz.app]
"C:\Users\King Technology\AppData\Local\Programs\Blitz\Blitz.exe" --autostart
04 - HKU\S-1-5-21-3516208702-2551172651-115148956-1002\..\Run : [ut] "C:\Users\King
Technology\AppData\Roaming\utorrent\updates\utorrent.exe" /MINIMIZED
04 - HKU\S-1-5-21-3516208702-2551172651-115148956-1002\..\Run : [Discord] "C:\
Users\King Technology\AppData\Local\Discord\Update.exe" --processStart Discord.exe
------------ | Tasks |
Task - Adobe Acrobat Update Task --> C:\Program Files (x86)\Common Files\Adobe\ARM\
1.0\AdobeARM.exe
Task - AdobeAAMUpdater-1.0-MicrosoftAccount-ahmedelsaidelgammal@hotmail.com --> C:\
Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe -
mode=scheduled
Task - AdobeGCInvoker-1.0 --> C:\Program Files (x86)\Common Files\Adobe\
AdobeGCClient\AGCInvokerUtility.exe -mode=scheduled
Task - GoogleUpdateTaskMachineCore{3204AE26-CD19-4625-88D9-4E779481654C} --> C:\
Program Files (x86)\Google\Update\GoogleUpdate.exe /c
Task - GoogleUpdateTaskMachineUA{3244745F-48B8-486D-9412-A7A39FC2E6FB} --> C:\
Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Task - Intel PTT EK Recertification --> "C:\Windows\System32\DriverStore\
FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\
IntelPTTEKRecertification.exe"
Task - MicrosoftEdgeUpdateTaskMachineCore --> C:\Program Files (x86)\Microsoft\
EdgeUpdate\MicrosoftEdgeUpdate.exe /c
Task - MicrosoftEdgeUpdateTaskMachineUA --> C:\Program Files (x86)\Microsoft\
EdgeUpdate\MicrosoftEdgeUpdate.exe /ua /installsource scheduler
Task - OneDrive Per-Machine Standalone Update Task --> C:\Program Files\Microsoft
OneDrive\OneDriveStandaloneUpdater.exe
Task - OneDrive Reporting Task-S-1-5-21-2562698828-2966984103-1666983262-500 -->
C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
Task - OneDrive Reporting Task-S-1-5-21-3516208702-2551172651-115148956-1002 -->
C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
Task - OneDrive Reporting Task-S-1-5-21-3516208702-2551172651-115148956-500 --> C:\
Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
Task - StartCN --> "C:\Program Files\AMD\CNext\CNext\cncmd.exe" startwithdelay
Task - StartDVR --> "C:\Program Files\AMD\CNext\CNext\RSServCmd.exe"
Task - UsbFix Boot Scan --> "C:\Program Files (x86)\UsbFix\UsbFix.exe" -scanonstart
Task - UsbFix Monitor --> "C:\Program Files (x86)\UsbFix\Modules\UsbFixMonitor.exe"
Task - User_Feed_Synchronization-{0961E8C9-62FB-4D4F-A556-BCB4D4B6A06B} --> C:\
Windows\system32\msfeedssync.exe sync
------------ | C:\ %SystemDrive% - Fixed drive (NTFS) |
[08/11/2022   -   15:24:16   |   A | 2 Ko] - AiOLog.txt
[09/11/2022   -   05:08:38   |   A | 0 Ko] - nsispromotion_log.txt
[08/03/2023   -   11:25:28   |   ASH | 8 Ko] - DumpStack.log.tmp
[08/03/2023   -   11:25:28   |   ASH | 16384 Ko] - swapfile.sys
[08/03/2023   -   22:33:42   |   ASH | 4980736 Ko] - pagefile.sys
[10/03/2023   -   11:30:16   |   ASH | 3313268 Ko] - hiberfil.sys
[02/03/2023   -   21:15:41   |   ASH | 8 Ko] - DumpStack.log
[09/11/2022   -   07:12:22   |   SHD] - $Recycle.Bin
[07/12/2019   -   11:14:52   |   D] - PerfLogs
[31/07/2022   -   01:34:29   |   SHD] - Documents and Settings
[08/11/2022   -   15:16:45   |   RD] - Users
[08/11/2022   -   15:21:27   |   HD] - $WinREAgent
[09/11/2022   -   00:57:31   |   SHD] - Recovery
[09/11/2022   -   01:10:29   |   D] - AMD
[09/11/2022   -   01:13:50   |   D] - DrvPath
[09/12/2022   -   01:35:06   |   D] - Autodesk
[04/01/2023   -   20:51:03   |   RD] - Program Files (x86)
[04/01/2023   -   20:53:15   |   AH | 0 Ko] - EBE21BC1DB11
[20/02/2023   -   06:00:46   |   D] - Riot Games
[02/03/2023   -   08:00:38   |   HD] - ProgramData
[08/03/2023   -   11:25:31   |   D] - Intel
[08/03/2023   -   19:38:05   |   D] - Windows
[10/03/2023   -   02:32:01   |   RD] - Program Files
------------ | D:\ - Fixed drive (NTFS) |
[09/11/2022 - 01:01:22 | SHD] - $RECYCLE.BIN
[21/02/2023 - 13:02:06 | D] - raot_2.086_windows
------------ | E:\ - Fixed drive (NTFS) |
[04/01/2023 - 20:45:10 | A | 1603239 Ko] -
Adobe_Photoshop_CC_2018_v19.1.7.16293x64.zip
[02/03/2023 - 07:36:26 | D] - Hogwarts.Legacy
[02/12/2006 - 09:37:14 | A | 884 Ko] - msdia80.dll
[09/11/2022 - 01:01:22 | SHD] - $RECYCLE.BIN
[04/01/2023 - 20:48:41 | D] - Adobe_Photoshop_CC_2018_v19.1.7.16293x64
[02/03/2023 - 07:36:03 | D] - courses
------------ | I:\ - Fixed drive (NTFS) |
[08/11/2022 - 15:35:48 | SHD] - $RECYCLE.BIN
Infected elements : 0
Analyzed elements : 101827 in 00h 00m 05s
# UsbFix-Report-31.txt [8447B]
------------ | E.O.F      |