Olá, estou com problemas de vírus no meu HD externo a um tempo, antes era aquele vírus das pastas que viram atalhos, li na internet e dei um jeito, agora tem várias pastas ocultas lá que não são minhas e não consigo deletar, achei o site e li sobre o Usb.fix, resolvi testar e aqui está meu relatório Usb.Fix, espero que consiga resolver, obrigada :(
[b]############################## | UsbFix V 7.176 | [Pesquisa][/b]
Usuário: Cecilia (Administrador) # CECILIA-HARRYP
Atualizado em 18/07/2014 por El Desaparecido - SosVirus
Começou em 14:50:36 | 24/07/2014
Site : [url=http://www.pt.usbfix.net/]http://www.pt.usbfix.net/[/url]
Changelog : [url=http://www.usbfix.net/maj/]
https://www.usb-antivirus.com/fr/maj/[/url]
Asistencia : [url=http://www.sosvirus.net/]
https://www.sosvirus.net/[/url]
Upload Malware : [url=http://www.sosvirus.net/upload_malware.php]http://www.sosvirus.net/upload_malware.php[/url]
Contato : [url=http://www.pt.usbfix.net/contato/]http://www.pt.usbfix.net/contato/[/url]
[b]################## | System information |[/b]
MB: Hewlett-Packard (1445)
CPU: AMD Turion(tm) II P560 Dual-Core Processor
RAM -> [Total : 3835 Mo | Free : 1035 Mo]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft(TM) Windows 7 Ultimate (6.1.7601 64-Bit) Service Pack 1
WB: Internet Explorer : 11.00.9600.16428
WB: Google Chrome : 36.0.1985.125
WB: Mozilla Firefox : 31.0
[b]################## | Security Information |[/b]
AV: AVG AntiVirus Free Edition 2014 [[b](!) Não ativo[/b] |Atualizado]
AS: Windows Defender [[b](!) Não ativo[/b] |Atualizado]
AS: AVG AntiVirus Free Edition 2014 [[b](!) Não ativo[/b] |Atualizado]
FW: Windows Firewall [[b](!) Não ativo[/b]]
SC: Security Center [Ativo]
WU: Windows Update [Ativo]
[b]################## | Disk Information |[/b]
C:\ (%SystemDrive%) -> Disco fixo # 466 Gb (366 Mb livre - 79%) [] # NTFS
E:\ -> Disco fixo # 932 Gb (494 Mb livre - 53%) [Princesa Jujuba] # NTFS
F:\ -> Disco removível # 4 Gb (2 Mb livre - 47%) [CECILIA] # FAT32
[b]################## | Processos Ativos |[/b]
C:\Windows\System32\smss.exe (ID: 272|ParentID: 4|SISTEMA)
C:\Windows\System32\wininit.exe (ID: 740|ParentID: 660)
C:\Windows\System32\services.exe (ID: 812|ParentID: 740)
C:\Windows\System32\winlogon.exe (ID: 840|ParentID: 752)
C:\Windows\System32\lsass.exe (ID: 868|ParentID: 740)
C:\Windows\System32\lsm.exe (ID: 888|ParentID: 740)
C:\Windows\System32\svchost.exe (ID: 972|ParentID: 812)
C:\PROGRA~2\GbPlugin\GbpSv.exe (ID: 308|ParentID: 812)
C:\Windows\System32\svchost.exe (ID: 680|ParentID: 812)
C:\Windows\System32\atiesrxx.exe (ID: 872|ParentID: 812)
C:\Windows\System32\svchost.exe (ID: 1068|ParentID: 812)
C:\Windows\System32\svchost.exe (ID: 1128|ParentID: 812)
C:\Windows\System32\svchost.exe (ID: 1168|ParentID: 812)
C:\Windows\System32\svchost.exe (ID: 1200|ParentID: 812)
C:\Windows\System32\audiodg.exe (ID: 1288|ParentID: 1068)
C:\Windows\System32\atieclxx.exe (ID: 1404|ParentID: 872)
C:\Windows\System32\svchost.exe (ID: 1472|ParentID: 812)
C:\Windows\System32\spoolsv.exe (ID: 1676|ParentID: 812)
C:\Windows\System32\svchost.exe (ID: 1708|ParentID: 812)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1800|ParentID: 812)
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (ID: 1820|ParentID: 812)
C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (ID: 1884|ParentID: 812)
C:\Windows\System32\svchost.exe (ID: 2488|ParentID: 812)
C:\Windows\System32\sppsvc.exe (ID: 2516|ParentID: 812)
C:\Windows\System32\svchost.exe (ID: 2132|ParentID: 812)
C:\Windows\System32\SearchIndexer.exe (ID: 1056|ParentID: 812)
C:\Windows\System32\taskhost.exe (ID: 3028|ParentID: 812|Cecilia)
C:\Windows\System32\dwm.exe (ID: 2400|ParentID: 1128|Cecilia)
C:\Windows\explorer.exe (ID: 2012|ParentID: 200|Cecilia)
C:\Program Files (x86)\uTorrent\uTorrent.exe (ID: 956|ParentID: 2012|Cecilia)
C:\Users\Cecilia\AppData\Local\Skillbrains\lightshot\5.1.4.6\Lightshot.exe (ID: 3092|ParentID: 3076|Cecilia)
C:\Program Files (x86)\Origin\Origin.exe (ID: 3148|ParentID: 2012|Cecilia)
C:\Program Files (x86)\AVG\AVG2014\avgui.exe (ID: 3304|ParentID: 3180|Cecilia)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ID: 3356|ParentID: 3288|Cecilia)
C:\Windows\SysWOW64\ctfmon.exe (ID: 4044|ParentID: 3304|Cecilia)
C:\PROGRA~2\Raptr\raptr.exe (ID: 3444|ParentID: 3084|Cecilia)
C:\PROGRA~2\Raptr\raptr_im.exe (ID: 3964|ParentID: 3444|Cecilia)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ID: 3336|ParentID: 3356|Cecilia)
C:\Program Files (x86)\Raptr\raptr_ep64.exe (ID: 2948|ParentID: 3444|Cecilia)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 4848|ParentID: 3180|Cecilia)
C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 3124|ParentID: 812)
C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ID: 3268|ParentID: 2012|Cecilia)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID: 4772|ParentID: 3268|Cecilia)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID: 1556|ParentID: 3268|Cecilia)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (ID: 4588|ParentID: 1556|Cecilia)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (ID: 4608|ParentID: 4588|Cecilia)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 2980|ParentID: 2012|Cecilia)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3500|ParentID: 2980|Cecilia)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4908|ParentID: 2980|Cecilia)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 640|ParentID: 2980|Cecilia)
C:\Program Files (x86)\Windows Media Player\wmplayer.exe (ID: 5716|ParentID: 2012|Cecilia)
C:\Program Files (x86)\Steam\Steam.exe (ID: 5264|ParentID: 5688|Cecilia)
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (ID: 592|ParentID: 5264|Cecilia)
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (ID: 5524|ParentID: 592|Cecilia)
C:\Program Files (x86)\Common Files\Steam\SteamService.exe (ID: 3244|ParentID: 812)
C:\Program Files (x86)\RaidCall.BR\raidcall.exe (ID: 4284|ParentID: 5284|Cecilia)
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (ID: 5188|ParentID: 592|Cecilia)
C:\Windows\SysWOW64\notepad.exe (ID: 5728|ParentID: 4020|Cecilia)
C:\UsbFix\UsbFix.exe (ID: 2292|ParentID: 2012|Cecilia)
[b]################## | Autorun |[/b]
[b]################## | Regedit Run |[/b]
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
04 - HKCU\..\Run : [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKCU\..\Run : [LightShot] C:\Users\Cecilia\AppData\Local\Skillbrains\lightshot\Lightshot.exe Flags: uninsdeletevalue
04 - HKCU\..\Run : [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup
04 - HKCU\..\Run : [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
04 - HKLM\..\Run : [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\..\Run : [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
04 - HKLM\..\Run : [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [AutoStarter] C:\ProgramData\AutoStarter\AutoStarter.exe
04 - HKLM\..\Run : [RaidCall] C:\Program Files (x86)\RaidCall.BR\raidcall.exe
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-1300132834-1479614385-35549922-1000\..\Run : [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
04 - HKU\S-1-5-21-1300132834-1479614385-35549922-1000\..\Run : [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKU\S-1-5-21-1300132834-1479614385-35549922-1000\..\Run : [LightShot] C:\Users\Cecilia\AppData\Local\Skillbrains\lightshot\Lightshot.exe Flags: uninsdeletevalue
04 - HKU\S-1-5-21-1300132834-1479614385-35549922-1000\..\Run : [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup
04 - HKU\S-1-5-21-1300132834-1479614385-35549922-1000\..\Run : [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-18\..\RunOnce : [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
https://support.microsoft.com/en-us/windows/install-windows-7-service-pack-1-sp1-b3da2c0f-cdb6-0572-8596-bab972897f61" /build:7601
[b]################## | Procura genérica |[/b]
Presente ! C:\Users\Cecilia\autorun.inf
Presente ! C:\Windows\Tasks\update-sys.job
Presente ! C:\Windows\Tasks\update-S-1-5-21-1300132834-1479614385-35549922-1000.job
[b]################## | Registro |[/b]
Presente ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DatamngrCoordinator.exe
[b]################## | E.O.F | [url=http://www.sosvirus.net/]
https://www.sosvirus.net/[/url] | [url=http://www.pt.usbfix.net/]http://www.pt.usbfix.net/[/url] |[/b]