Ir para conteúdo

Foto

Problema com o "wscript.exe - Sem disco"

wscript.exe; malware wscript.exe malware

Este tópico foi arquivado. Isto significa que você não pode mais responder ao tópico.
10 respostas neste tópico

#1
JohnsonK

JohnsonK

    Novato

  • Novato
  • Pip
  • 6 posts

A pedido de um amigo coloquei um cartão de memória da câmera dele e logo o avira bloqueou seu funcionamento. Fiz a varredura e depois cliquei em excluir o arquivo. Em seguida ele tornou a pedir que conectasse o cartão no PC pois precisava das fotos. Fiz a varredura novamente e a pasta não foi iniciada. Em seguida abri manualmente e ao ejetar o cartão, começou a aparecer a mensagem de erro "wscript.exe - Sem disco" Não á nenhum disco na unidade. Insira um disco na unidade G:. -(Cancelar/Tentar/Continuar). Essa caixa não pode ser fechada e permanece piscando na tela independente da opção que você clica.Como prosseguir para solucionar esse problema?!

Não foi possível anexar o log do MBRScan devido ao tamanho do arquivo, disponibilizo a seguir:

 

MBRScan v1.1.1
 
OS             : Windows 8  (64 bit)
PROCESSOR      : Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
BOOT           : Normal Boot
DATE           : 2013/06/30 (ISO 8601) at 21:58:59
________________________________________________________________________________
 
DISK           : Device\Harddisk0\DR0 __WDC WD5000BPVT-00HXZT3 (01.01A01)
BUS_TYPE       : (0x03)  P-ATA
USE_PIO        : NO
MAX_TRANSFER   : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________
 
Device\Harddisk0\DR0 465.8 Go  [Fixed] ==> 7 MBR Code
 
MBR_MD5   : 02E5D29C11FC6780375D8BB439E526C6
MBR_SHA1  : 30763486657E3B87B09D3E424CEAA77B1E0712AD
 
Device\Harddisk0\Partition1 200.0 Mo   0x07 NTFS / HPFS __ BOOTABLE __
Device\Harddisk0\Partition2 465.6 Go   0x07 NTFS / HPFS
________________________________________________________________________________
 
############################### Additional scan ################################
 
DRIVER  : C:\Windows\system32\ntoskrnl.exe => Invisible on the disk
ADDRESS : 0x98089000
SIZE    : 7.30 Mo
 
DRIVER  : C:\Windows\system32\hal.dll => Invisible on the disk
ADDRESS : 0x9801D000
SIZE    : 432.0 Ko
 
DRIVER  : C:\Windows\system32\kd.dll => Invisible on the disk
ADDRESS : 0x97036000
SIZE    : 36.0 Ko
 
DRIVER  : C:\Windows\system32\mcupdate_GenuineIntel.dll => Invisible on the disk
ADDRESS : 0x00C48000
SIZE    : 380.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\CLFS.SYS => Invisible on the disk
ADDRESS : 0x00CA7000
SIZE    : 368.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\tm.sys => Invisible on the disk
ADDRESS : 0x00D03000
SIZE    : 140.0 Ko
 
DRIVER  : C:\Windows\system32\CI.dll => Invisible on the disk
ADDRESS : 0x00D45000
SIZE    : 508.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\msrpc.sys => Invisible on the disk
ADDRESS : 0x0105F000
SIZE    : 396.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\Wdf01000.sys => Invisible on the disk
ADDRESS : 0x010C2000
SIZE    : 776.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\WDFLDR.SYS => Invisible on the disk
ADDRESS : 0x01184000
SIZE    : 64.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\acpiex.sys => Invisible on the disk
ADDRESS : 0x01194000
SIZE    : 92.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\WppRecorder.sys => Invisible on the disk
ADDRESS : 0x011AB000
SIZE    : 44.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\ACPI.sys => Invisible on the disk
ADDRESS : 0x00E88000
SIZE    : 436.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\WMILIB.SYS => Invisible on the disk
ADDRESS : 0x00EF5000
SIZE    : 40.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\msisadrv.sys => Invisible on the disk
ADDRESS : 0x00EFF000
SIZE    : 40.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\pci.sys => Invisible on the disk
ADDRESS : 0x00F09000
SIZE    : 244.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\cng.sys => Invisible on the disk
ADDRESS : 0x00F46000
SIZE    : 560.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\tpm.sys => Invisible on the disk
ADDRESS : 0x00FD2000
SIZE    : 160.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\vdrvroot.sys => Invisible on the disk
ADDRESS : 0x00E00000
SIZE    : 52.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\pdc.sys => Invisible on the disk
ADDRESS : 0x00E0D000
SIZE    : 92.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\partmgr.sys => Invisible on the disk
ADDRESS : 0x00E24000
SIZE    : 104.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\spaceport.sys => Invisible on the disk
ADDRESS : 0x00E3E000
SIZE    : 292.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\volmgr.sys => Invisible on the disk
ADDRESS : 0x011B6000
SIZE    : 96.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\volmgrx.sys => Invisible on the disk
ADDRESS : 0x012C9000
SIZE    : 384.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\pciide.sys => Invisible on the disk
ADDRESS : 0x01329000
SIZE    : 32.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\PCIIDEX.SYS => Invisible on the disk
ADDRESS : 0x01331000
SIZE    : 60.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\mountmgr.sys => Invisible on the disk
ADDRESS : 0x01340000
SIZE    : 104.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\atapi.sys => Invisible on the disk
ADDRESS : 0x0135A000
SIZE    : 40.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\ataport.SYS => Invisible on the disk
ADDRESS : 0x01364000
SIZE    : 208.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\fltmgr.sys => Invisible on the disk
ADDRESS : 0x01200000
SIZE    : 384.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\fileinfo.sys => Invisible on the disk
ADDRESS : 0x01260000
SIZE    : 80.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\Ntfs.sys => Invisible on the disk
ADDRESS : 0x01418000
SIZE    : 1.89 Mo
 
DRIVER  : C:\Windows\System32\Drivers\ksecdd.sys => Invisible on the disk
ADDRESS : 0x01274000
SIZE    : 108.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\pcw.sys => Invisible on the disk
ADDRESS : 0x01400000
SIZE    : 68.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\Fs_Rec.sys => Invisible on the disk
ADDRESS : 0x0128F000
SIZE    : 40.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\ndis.sys => Invisible on the disk
ADDRESS : 0x016BA000
SIZE    : 996.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\NETIO.SYS => Invisible on the disk
ADDRESS : 0x01600000
SIZE    : 444.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\ksecpkg.sys => Invisible on the disk
ADDRESS : 0x0166F000
SIZE    : 188.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\tcpip.sys => Invisible on the disk
ADDRESS : 0x01A75000
SIZE    : 2.22 Mo
 
DRIVER  : C:\Windows\System32\drivers\fwpkclnt.sys => Invisible on the disk
ADDRESS : 0x01CAE000
SIZE    : 416.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\wfplwfs.sys => Invisible on the disk
ADDRESS : 0x01D16000
SIZE    : 108.0 Ko
 
DRIVER  : C:\Windows\System32\DRIVERS\fvevol.sys => Invisible on the disk
ADDRESS : 0x01D31000
SIZE    : 472.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\volsnap.sys => Invisible on the disk
ADDRESS : 0x01DA7000
SIZE    : 340.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\rdyboost.sys => Invisible on the disk
ADDRESS : 0x01A00000
SIZE    : 236.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\mup.sys => Invisible on the disk
ADDRESS : 0x01A3B000
SIZE    : 92.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\disk.sys => Invisible on the disk
ADDRESS : 0x0169E000
SIZE    : 112.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\CLASSPNP.SYS => Invisible on the disk
ADDRESS : 0x01000000
SIZE    : 336.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\crashdmp.sys => Invisible on the disk
ADDRESS : 0x01A5E000
SIZE    : 80.0 Ko
 
DRIVER  : C:\Windows\System32\DRIVERS\cmderd.sys => Invisible on the disk
ADDRESS : 0x017D4000
SIZE    : 36.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\cdrom.sys => Invisible on the disk
ADDRESS : 0x013B2000
SIZE    : 196.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\cmdguard.sys => Invisible on the disk
ADDRESS : 0x03459000
SIZE    : 712.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\Null.SYS => Invisible on the disk
ADDRESS : 0x0350B000
SIZE    : 36.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\Beep.SYS => Invisible on the disk
ADDRESS : 0x03514000
SIZE    : 32.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\BasicRender.sys => Invisible on the disk
ADDRESS : 0x0351C000
SIZE    : 52.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\dxgkrnl.sys => Invisible on the disk
ADDRESS : 0x03A0A000
SIZE    : 1.41 Mo
 
DRIVER  : C:\Windows\System32\drivers\watchdog.sys => Invisible on the disk
ADDRESS : 0x03B73000
SIZE    : 68.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\dxgmms1.sys => Invisible on the disk
ADDRESS : 0x03B84000
SIZE    : 312.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\BasicDisplay.sys => Invisible on the disk
ADDRESS : 0x03BD2000
SIZE    : 68.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\Npfs.SYS => Invisible on the disk
ADDRESS : 0x03BE3000
SIZE    : 72.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\Msfs.SYS => Invisible on the disk
ADDRESS : 0x03529000
SIZE    : 48.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\tdx.sys => Invisible on the disk
ADDRESS : 0x03535000
SIZE    : 136.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\TDI.SYS => Invisible on the disk
ADDRESS : 0x03557000
SIZE    : 56.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\cmdhlp.sys => Invisible on the disk
ADDRESS : 0x03565000
SIZE    : 48.0 Ko
 
DRIVER  : C:\Windows\System32\DRIVERS\netbt.sys => Invisible on the disk
ADDRESS : 0x03571000
SIZE    : 352.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\afd.sys => Invisible on the disk
ADDRESS : 0x03C60000
SIZE    : 584.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\pacer.sys => Invisible on the disk
ADDRESS : 0x03CF2000
SIZE    : 168.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\vwififlt.sys => Invisible on the disk
ADDRESS : 0x03D1C000
SIZE    : 88.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\inspect.sys => Invisible on the disk
ADDRESS : 0x03D32000
SIZE    : 124.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\netbios.sys => Invisible on the disk
ADDRESS : 0x03D51000
SIZE    : 64.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\avkmgr.sys => Invisible on the disk
ADDRESS : 0x03D61000
SIZE    : 40.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\avipbb.sys => Invisible on the disk
ADDRESS : 0x03D6B000
SIZE    : 144.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\rdbss.sys => Invisible on the disk
ADDRESS : 0x03E98000
SIZE    : 460.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\wanarp.sys => Invisible on the disk
ADDRESS : 0x03F0B000
SIZE    : 104.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\nsiproxy.sys => Invisible on the disk
ADDRESS : 0x03F25000
SIZE    : 56.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\npsvctrig.sys => Invisible on the disk
ADDRESS : 0x03F33000
SIZE    : 48.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\mssmbios.sys => Invisible on the disk
ADDRESS : 0x03F3F000
SIZE    : 48.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\discache.sys => Invisible on the disk
ADDRESS : 0x03F4B000
SIZE    : 68.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\dfsc.sys => Invisible on the disk
ADDRESS : 0x03F5C000
SIZE    : 132.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\AppleCharger.sys => Invisible on the disk
ADDRESS : 0x03F8F000
SIZE    : 32.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\ndistapi.sys => Invisible on the disk
ADDRESS : 0x03F97000
SIZE    : 48.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\ndiswan.sys => Invisible on the disk
ADDRESS : 0x03FA3000
SIZE    : 188.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\rassstp.sys => Invisible on the disk
ADDRESS : 0x03FD2000
SIZE    : 120.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\AgileVpn.sys => Invisible on the disk
ADDRESS : 0x03E00000
SIZE    : 96.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\tunnel.sys => Invisible on the disk
ADDRESS : 0x03E18000
SIZE    : 176.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\CompositeBus.sys => Invisible on the disk
ADDRESS : 0x03E44000
SIZE    : 60.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\kdnic.sys => Invisible on the disk
ADDRESS : 0x03E53000
SIZE    : 44.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\umbus.sys => Invisible on the disk
ADDRESS : 0x03E5E000
SIZE    : 72.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\nvlddmkm.sys => Invisible on the disk
ADDRESS : 0x0408F000
SIZE    : 10.66 Mo
 
DRIVER  : C:\Windows\System32\drivers\HDAudBus.sys => Invisible on the disk
ADDRESS : 0x04B37000
SIZE    : 88.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\usbehci.sys => Invisible on the disk
ADDRESS : 0x04B4D000
SIZE    : 88.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\USBPORT.SYS => Invisible on the disk
ADDRESS : 0x04B63000
SIZE    : 492.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\Rt630x64.sys => Invisible on the disk
ADDRESS : 0x04CED000
SIZE    : 592.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\intelppm.sys => Invisible on the disk
ADDRESS : 0x04D81000
SIZE    : 112.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\raspptp.sys => Invisible on the disk
ADDRESS : 0x04D9D000
SIZE    : 132.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\rasl2tp.sys => Invisible on the disk
ADDRESS : 0x04DBE000
SIZE    : 148.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\raspppoe.sys => Invisible on the disk
ADDRESS : 0x04DE3000
SIZE    : 104.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\swenum.sys => Invisible on the disk
ADDRESS : 0x04DFD000
SIZE    : 8.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\ks.sys => Invisible on the disk
ADDRESS : 0x04C00000
SIZE    : 316.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\rdpbus.sys => Invisible on the disk
ADDRESS : 0x04C4F000
SIZE    : 44.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\NDProxy.SYS => Invisible on the disk
ADDRESS : 0x04C5A000
SIZE    : 80.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\usbhub.sys => Invisible on the disk
ADDRESS : 0x04C6E000
SIZE    : 504.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\USBD.SYS => Invisible on the disk
ADDRESS : 0x04BDE000
SIZE    : 44.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\nvhda64v.sys => Invisible on the disk
ADDRESS : 0x04000000
SIZE    : 204.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\portcls.sys => Invisible on the disk
ADDRESS : 0x04033000
SIZE    : 300.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\drmk.sys => Invisible on the disk
ADDRESS : 0x03E70000
SIZE    : 136.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\ksthunk.sys => Invisible on the disk
ADDRESS : 0x0407E000
SIZE    : 24.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\RTKVHD64.sys => Invisible on the disk
ADDRESS : 0x05C3C000
SIZE    : 4.51 Mo
 
DRIVER  : C:\Windows\System32\drivers\usbccgp.sys => Invisible on the disk
ADDRESS : 0x060BF000
SIZE    : 140.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\USBSTOR.SYS => Invisible on the disk
ADDRESS : 0x060E2000
SIZE    : 124.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\hidusb.sys => Invisible on the disk
ADDRESS : 0x06101000
SIZE    : 52.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\HIDCLASS.SYS => Invisible on the disk
ADDRESS : 0x0610E000
SIZE    : 108.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\HIDPARSE.SYS => Invisible on the disk
ADDRESS : 0x06129000
SIZE    : 32.0 Ko
 
DRIVER  : C:\Windows\System32\win32k.sys => Invisible on the disk
ADDRESS : 0x001F9000
SIZE    : 3.94 Mo
 
DRIVER  : C:\Windows\System32\drivers\dc3d.sys => Invisible on the disk
ADDRESS : 0x0618E000
SIZE    : 92.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\usbvideo.sys => Invisible on the disk
ADDRESS : 0x061A5000
SIZE    : 208.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\usbaudio.sys => Invisible on the disk
ADDRESS : 0x061D9000
SIZE    : 120.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\kbdhid.sys => Invisible on the disk
ADDRESS : 0x05C00000
SIZE    : 52.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\kbdclass.sys => Invisible on the disk
ADDRESS : 0x05C0D000
SIZE    : 60.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\mouhid.sys => Invisible on the disk
ADDRESS : 0x05C1C000
SIZE    : 48.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\point64.sys => Invisible on the disk
ADDRESS : 0x05C28000
SIZE    : 68.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\mouclass.sys => Invisible on the disk
ADDRESS : 0x06131000
SIZE    : 60.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\dump_dumpata.sys => Invisible on the disk
ADDRESS : 0x06140000
SIZE    : 52.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\dump_atapi.sys => Invisible on the disk
ADDRESS : 0x0614D000
SIZE    : 40.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\dump_dumpfve.sys => Invisible on the disk
ADDRESS : 0x06157000
SIZE    : 80.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\monitor.sys => Invisible on the disk
ADDRESS : 0x0616B000
SIZE    : 56.0 Ko
 
DRIVER  : C:\Windows\System32\TSDDD.dll => Invisible on the disk
ADDRESS : 0x006CA000
SIZE    : 36.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\BdaSup.SYS => Invisible on the disk
ADDRESS : 0x06179000
SIZE    : 20.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\luafv.sys => Invisible on the disk
ADDRESS : 0x03DAA000
SIZE    : 160.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\avgntflt.sys => Invisible on the disk
ADDRESS : 0x03DD2000
SIZE    : 128.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\lltdio.sys => Invisible on the disk
ADDRESS : 0x04BE9000
SIZE    : 80.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\nwifi.sys => Invisible on the disk
ADDRESS : 0x08C00000
SIZE    : 440.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\ndisuio.sys => Invisible on the disk
ADDRESS : 0x08C6E000
SIZE    : 80.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\rspndr.sys => Invisible on the disk
ADDRESS : 0x08C82000
SIZE    : 96.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\HTTP.sys => Invisible on the disk
ADDRESS : 0x08C9A000
SIZE    : 892.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\bowser.sys => Invisible on the disk
ADDRESS : 0x08D79000
SIZE    : 128.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\mpsdrv.sys => Invisible on the disk
ADDRESS : 0x08D99000
SIZE    : 92.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\mrxsmb.sys => Invisible on the disk
ADDRESS : 0x0943E000
SIZE    : 396.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\mrxsmb10.sys => Invisible on the disk
ADDRESS : 0x094A1000
SIZE    : 300.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\mrxsmb20.sys => Invisible on the disk
ADDRESS : 0x094EC000
SIZE    : 236.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\Ndu.sys => Invisible on the disk
ADDRESS : 0x09527000
SIZE    : 112.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\peauth.sys => Invisible on the disk
ADDRESS : 0x096A0000
SIZE    : 816.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\secdrv.SYS => Invisible on the disk
ADDRESS : 0x0976C000
SIZE    : 44.0 Ko
 
DRIVER  : C:\Windows\System32\DRIVERS\srvnet.sys => Invisible on the disk
ADDRESS : 0x09777000
SIZE    : 272.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\tcpipreg.sys => Invisible on the disk
ADDRESS : 0x097BB000
SIZE    : 72.0 Ko
 
DRIVER  : C:\Windows\System32\DRIVERS\srv2.sys => Invisible on the disk
ADDRESS : 0x09543000
SIZE    : 644.0 Ko
 
DRIVER  : C:\Windows\System32\DRIVERS\srv.sys => Invisible on the disk
ADDRESS : 0x09600000
SIZE    : 564.0 Ko
 
DRIVER  : C:\Windows\system32\drivers\WudfPf.sys => Invisible on the disk
ADDRESS : 0x097CD000
SIZE    : 100.0 Ko
 
DRIVER  : C:\Windows\system32\DRIVERS\WUDFRd.sys => Invisible on the disk
ADDRESS : 0x09400000
SIZE    : 216.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\WpdUpFltr.sys => Invisible on the disk
ADDRESS : 0x097E6000
SIZE    : 44.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\condrv.sys => Invisible on the disk
ADDRESS : 0x097F1000
SIZE    : 52.0 Ko
 
DRIVER  : C:\Windows\SysWOW64\Drivers\X6va012 => Invisible on the disk
ADDRESS : 0x0968D000
SIZE    : 28.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\fastfat.SYS => Invisible on the disk
ADDRESS : 0x08DB0000
SIZE    : 220.0 Ko
 
DRIVER  : C:\Windows\System32\drivers\rdpvideominiport.sys => Invisible on the disk
ADDRESS : 0x09694000
SIZE    : 44.0 Ko
 
DRIVER  : C:\Windows\System32\cdd.dll => Invisible on the disk
ADDRESS : 0x008AB000
SIZE    : 216.0 Ko
 
DRIVER  : C:\Windows\System32\Drivers\KWORLD_UB320i.sys => Invisible on the disk
ADDRESS : 0x03C36000
SIZE    : 108.0 Ko
 
BCD EmsSettings {0CE4991B-E6B3-4B16-B23C-5E0D9250E5D9} => BcdLibraryBoolean_EmsEnabled (16000020)
 
SystemStartOptions :  NOEXECUTE=OPTIN
 
________________________________________________________________________________
 
_______MBR   \Device\Harddisk0\DR0  
 
0x00000000   33 C0 8E D0 BC 00 7C 8E C0 8E D8 BE 00 7C BF 00   3À.м.|.À.ؾ.|¿.
0x00000010   06 B9 00 02 FC F3 A4 50 68 1C 06 CB FB B9 04 00   .¹..üó¤Ph..Ëû¹..
0x00000020   BD BE 07 80 7E 00 00 7C 0B 0F 85 0E 01 83 C5 10   ½¾..~..|......Å.
0x00000030   E2 F1 CD 18 88 56 00 55 C6 46 11 05 C6 46 10 00   âñÍ..V.UÆF..ÆF..
0x00000040   B4 41 BB AA 55 CD 13 5D 72 0F 81 FB 55 AA 75 09   ´A»ªUÍ.]r..ûUªu.
0x00000050   F7 C1 01 00 74 03 FE 46 10 66 60 80 7E 10 00 74   ÷Á..t.þF.f`.~..t
0x00000060   26 66 68 00 00 00 00 66 FF 76 08 68 00 00 68 00   &fh....f.v.h..h.
0x00000070   7C 68 01 00 68 10 00 B4 42 8A 56 00 8B F4 CD 13   |h..h..´B.V..ôÍ.
0x00000080   9F 83 C4 10 9E EB 14 B8 01 02 BB 00 7C 8A 56 00   ..Ä..ë.¸..».|.V.
0x00000090   8A 76 01 8A 4E 02 8A 6E 03 CD 13 66 61 73 1C FE   .v..N..n.Í.fas.þ
0x000000A0   4E 11 75 0C 80 7E 00 80 0F 84 8A 00 B2 80 EB 84   N.u..~......².ë.
0x000000B0   55 32 E4 8A 56 00 CD 13 5D EB 9E 81 3E FE 7D 55   U2ä.V.Í.]ë..>þ}U
0x000000C0   AA 75 6E FF 76 00 E8 8D 00 75 17 FA B0 D1 E6 64   ªun.v.è..u.ú°Ñæd
0x000000D0   E8 83 00 B0 DF E6 60 E8 7C 00 B0 FF E6 64 E8 75   è..°ßæ`è|.°.ædèu
0x000000E0   00 FB B8 00 BB CD 1A 66 23 C0 75 3B 66 81 FB 54   .û¸.»Í.f#Àu;f.ûT
0x000000F0   43 50 41 75 32 81 F9 02 01 72 2C 66 68 07 BB 00   CPAu2.ù..r,fh.».
0x00000100   00 66 68 00 02 00 00 66 68 08 00 00 00 66 53 66   .fh....fh....fSf
0x00000110   53 66 55 66 68 00 00 00 00 66 68 00 7C 00 00 66   SfUfh....fh.|..f
0x00000120   61 68 00 00 07 CD 1A 5A 32 F6 EA 00 7C 00 00 CD   ah...Í.Z2öê.|..Í
0x00000130   18 A0 B7 07 EB 08 A0 B6 07 EB 03 A0 B5 07 32 E4   ..·.ë..¶.ë..µ.2ä
0x00000140   05 00 07 8B F0 AC 3C 00 74 09 BB 07 00 B4 0E CD   ....ð¬<.t.»..´.Í
0x00000150   10 EB F2 F4 EB FD 2B C9 E4 64 EB 00 24 02 E0 F8   .ëòôëý+Éädë.$.àø
0x00000160   24 02 C3 49 6E 76 61 6C 69 64 20 70 61 72 74 69   $.ÃInvalid parti
0x00000170   74 69 6F 6E 20 74 61 62 6C 65 00 45 72 72 6F 72   tion table.Error
0x00000180   20 6C 6F 61 64 69 6E 67 20 6F 70 65 72 61 74 69    loading operati
0x00000190   6E 67 20 73 79 73 74 65 6D 00 4D 69 73 73 69 6E   ng system.Missin
0x000001A0   67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74   g operating syst
0x000001B0   65 6D 00 00 00 63 7B 9A D7 0B 02 23 00 00 80 20   em...c{.×..#... 
0x000001C0   21 00 07 9F 06 19 00 08 00 00 00 40 06 00 00 9F   !..........@....
0x000001D0   07 19 07 FE FF FF 00 48 06 00 00 10 32 3A 00 00   ...þ...H....2:..
0x000001E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª
 

Arquivo(s) anexado(s)


Editado por JohnsonK, 30 junho 2013 - 22:16.


#2
CarlosTurco

CarlosTurco

    Assistente

  • Assistente
  • 23.609 posts

JohnsonK,

 

Por favor, observe o seguinte:

  • NÃO tente realizar sozinho nenhum procedimento de limpeza. Em especial, não execute por conta própria ferramentas utilizadas no fórum Remoção de Malware. O uso indevido de algumas ferramentas poderá danificar o seu computador ou, no mínimo, remover parcialmente os sinais de uma infecção que serviriam de informação ao analista. A equipe não será responsabilizada por consequências resultantes de uso indevido e/ou não-informado das ferramentas. - Regra nº8 da Remoção de Malwares
  • Não inicie novo tópico sobre esse problema. Poste suas respostas sempre neste tópico.
  • Clique em button_seguir.png (se localiza no canto superior direito do post principal) para que receba notificação por e-mail quando o mesmo for respondido. Você também pode verificar os tópicos assinados usando a opção Conteúdo que sigo acessível através do Painel de Controle do fórum.
  • As análises podem levar algum tempo, portanto seja paciente.
  • As instruções são específicas para o seu computador, e devem ser aplicadas somente nele.
  • Se algo der errado, não importa. Sempre acompanhe seu tópico, informando-me dos resultados, até que seu computador esteja limpo.
  • Aviso: Evite utilizar as tags <QUOTE> ou <CODE> nos logs, isso prejudica a leitura na hora da analise.
  • Não abandone seu tópico. Para nós é importante saber se a remoção foi bem sucedida.
  • Se você não receber uma resposta minha em até 5 dias. Me envie uma MP

 

worm.png Seu computador está infectado com um tipo de worm que se espalha através de qualquer tipo de dispositivo de armazenamento removível (pendrives, mp3, mp4, celulares, cartões de memória, câmeras fotográficas) e também através de outras máquinas ligadas em rede.

Para evitar que seu computador seja reinfectado, e para não infectar outros computadores, é necessário que você formate o dispositivo em questão.
Se houver mais de um, todos devem ser formatados e não devem ser utilizados em nenhum pc até que terminemos a limpeza, de modo a conseguirmos desinfectar este computador.

É recomendável que você troque todas as senhas armazenadas neste pc. Se você usou ou usa o internet banking, comunique suas instituições financeiras sobre o ocorrido e troque as senhas urgentemente.

Faça o download do Panda USB Vaccine e salve na sua área de trabalho.

  • Conecte todos os dispositivos de armazenamento removível nas portas USBs. Salve o que achar necessário, EXCETO arquivos executáveis, depois formate as mídias, indo em Meu Computador e clicando com o direito sobre a unidade da mídia, escolhendo a opção "Formatar"
  • Execute o Panda USB Vaccine
  • Vá seguindo os prompts que poderão aparecer.
  • Espere até que o programa conclua a busca e depois saia do programa.

 

Ainda com as mídias plugadas nas USB, vamos à próxima etapa:

 

Desative seu antivírus, antispyware e firewall, para não causar conflitos.

Baixe o Dr.Web CureIt!

O programa será baixado automaticamente. Salve-o na sua Área de Trabalho.

  • Dê um duplo clique sobre o arquivo drweb-cureit.exe, e clique em Executar na janela de aviso de segurança.
  • O Dr.Web será iniciado no Enhanced Protection Mode (EPM). Dê o Cancel para que seja executado no modo normal.
  • Marque a caixa que permite o envio de estatísticas, e clique em Continue.
  • Clique no botão 2iqy61j.png, e clique em Portuguese.
  • Clique no botão bjbceu.jpg, e clique em Definições
  • Clique em Registro e em Especificar o nivel de registro deixe em Mínimo e clique em OK.
    23utt9v.png
  • Clique em Select objects for scanning, embaixo do botão Iniciar Exame
  • Clique em click para selecionar, marque a caixa My computer, depois clique em Ok.
  • Clique na caixa ao lado de Objetos Examinados, e em seguida em nnscja.png

O scan pode demorar, tenha paciência.



  • Se o programa pedir para reiniciar o computador durante a remoção, reinicie e aguarde para que ele termine de neutralizar as ameaças após o reboot.
  • Ao término da varredura, clique no botão 359jt09.png, caso tenham sido encontradas ameaças.
  • Clique em Open Report.
  • Será aberta uma janela do bloco de notas contendo informações. Selecione seu conteúdo, clique com o botão direito sobre a seleção e escolha Copiar. Cole o conteúdo na próxima resposta.

Poste também um novo log do HijackThis.



#3
JohnsonK

JohnsonK

    Novato

  • Novato
  • Pip
  • 6 posts

Aqui está o log scan do Dr. Web

 

=============================================================================
Dr.Web Scanner SE for Windows v8.2.0.05230
© Doctor Web, Ltd., 1992-2013
Scan session started 2013/07/01 10:52:09 
Module location : C:\Users\Johnson\AppData\Local\Temp\6E18E884-EEE270E8-8093A2D0-9B2726D0\
=============================================================================
OPTION [Automatic Apply Actions] NO
OPTION [Turn Off Computer After Scan] NO
OPTION [Use Sound Alerts] NO
OPTION [Block Network] NO
OPTION [Protect Process] NO
OPTION [Protect Raw Disk] NO
Using language: "English"
Available instances: 12
Instances used: 12
Platform: Windows 8 Starter x64/WOW (Build 9200)
API Version: 2.2
Scanning Engine version: 8.1.0.6170
Virus Finding Engine version: 7.0.4.9250
Total 121 virus bases are loaded from C:\Users\Johnson\AppData\Local\Temp\6E18E884-EEE270E8-8093A2D0-9B2726D0
07pa931w 7.0 bbe7c7b3a3c63ab0d27ae3cfc621a6d49b740e48 2013/07/01 07:40:33 1822 records - OK
gau5b2hq 7.0 215c2d42a54f5188e8159bfd122292450d16f29b 2011/07/25 11:20:03 2 records - OK
az83p58q 7.0 fa04678f170a21ec39077750c8424cfc0f225584 2013/07/01 00:08:41 1 record - OK
laqgny4d 7.0 613a3e4bae38b4e00a7432c24a9cd916fb1c654f 2013/07/01 00:06:34 24654 records - OK
gfivwji6 7.0 b81132c4abffd4d2949531a1219b6bb1c3bad6f7 2013/06/24 00:06:30 14062 records - OK
ua5ygcla 7.0 9aab251475626c658b193cfa2b5f91da471bf8f2 2013/06/17 00:05:57 13350 records - OK
vl6x1jg7 7.0 e1f8aca88745fcdd49dc7ae75e142c41e1faf178 2013/06/10 00:08:13 26371 records - OK
2rg5c02s 7.0 4e8627555a073f6bad5218bad3e69ebc4b93069f 2013/06/03 00:07:47 25525 records - OK
msdlbumv 7.0 f562371c5115143824efde38c9567c34ccbe5d1a 2013/05/27 00:16:19 33200 records - OK
u8a8ygx7 7.0 eccb30ec8ed44456f9b88fe96d9fe0de40e4fa51 2013/05/20 00:11:05 46384 records - OK
ftxh022j 7.0 9b481fbfbe1f564a84f21552da1d30d24e7b01db 2013/05/13 00:07:01 34270 records - OK
xhx25x5h 7.0 1bf754dd720727b5d6803e081c16ff7f4ba7b40b 2013/05/06 00:08:46 41611 records - OK
5fec29vr 7.0 4e883c92513c2d991968fb3e4f27910a63d9a2df 2013/04/29 00:06:36 36105 records - OK
v4gwq06e 7.0 b047d178295ecde53c3cf1c34e4361004569fa33 2013/04/22 00:07:26 31319 records - OK
fknk2ga0 7.0 9207e55a924e4aa989dfde4d8d219cf5cc200ce2 2013/04/15 00:07:56 28216 records - OK
4t8q6jl1 7.0 78855cfb9fbc063889c5405a577fe73188f08789 2013/04/08 00:05:35 23589 records - OK
lkr3hq0s 7.0 cec6d34c79d50608520e81b90a23d91f39df0b27 2013/04/01 00:07:37 26946 records - OK
af9yisir 7.0 fd3c78d78ea4dae4e252a7f7d76db22e1a679be9 2013/03/25 00:05:37 34778 records - OK
bcx8r9ze 7.0 268e71b1123ab5e60fd2f38d269fe5f3d22b3697 2013/03/18 00:06:19 11271 records - OK
m2mbvyvh 7.0 d196879775b0dc0ee8286f2e4def9adedb5b88df 2013/03/11 00:05:36 12046 records - OK
9tfyxh22 7.0 0db61d4e3235481da8493523538ced712db362c2 2013/03/04 00:05:18 21747 records - OK
ojdqayb8 7.0 65f99faf227b51883c9f1c854a3f76806b60affb 2013/02/25 00:06:28 11540 records - OK
dsysogkk 7.0 17bd7383b9c4b214c5c9029171db8ae1455984a0 2013/02/18 00:06:38 15568 records - OK
m8wgshci 7.0 cbe8774953ae403e49370d552b522a5839aa9fdb 2013/02/11 00:06:00 18805 records - OK
zaat1f62 7.0 fb6865c02a3680338e4ee0603579107227313b2b 2013/02/04 00:06:01 32488 records - OK
2ixpn8mc 7.0 95fcd2e24cd9b2ec2610656ffa70b8bf46e86a8b 2013/01/28 00:04:52 15470 records - OK
of94ow0h 7.0 3d710b3dd4580a7eca8c74d2c886d48f5b8b5172 2013/01/21 00:06:27 30093 records - OK
1xiaa9gg 7.0 bddde0b5426b7e5bebd61e1239ca529c87ae6e36 2013/01/14 00:04:41 16158 records - OK
lg84572c 7.0 bc40bd9330301e8d7796f489d03357fb711b3121 2013/01/07 00:04:45 19597 records - OK
9dvofzbx 7.0 805b6089c867549c75f843eac96b759c3f8d101f 2012/12/31 00:05:41 18184 records - OK
oty7up69 7.0 c12a817c1f95bb9fd8238ef0d5f68868a8d95686 2012/12/24 00:05:33 30183 records - OK
8fj474fk 7.0 33def496782eb5b7b1cc93fdb036a1b62fa6a2fd 2012/12/17 00:06:21 25519 records - OK
tqcfcpxt 7.0 422abae03c588822f412aa9aae50578a1d61737e 2012/12/10 00:05:04 20358 records - OK
6qvtl81v 7.0 a4f0d0ecad4fb6e0afdb1925f4e0b7863b9d03fa 2012/12/03 00:06:19 20133 records - OK
5cv2ct20 7.0 86daa918ee3de1e4c1e5dea6f9b5f63544cf8814 2012/11/26 00:05:22 27311 records - OK
ukc4wq20 7.0 6556881c748e1f894eb9c7943ebae67017e1aec2 2012/11/19 00:06:09 29434 records - OK
a4r65qh2 7.0 559141ef34f9e6226bb58560e9b52e4cc5165150 2012/11/12 00:06:22 26900 records - OK
5g3f4awx 7.0 cc55013e63ff89319ec772e34d77056c7108cd3b 2012/11/05 00:05:22 25164 records - OK
pjy4858c 7.0 f477dc247d9b562bb64fd4f46a7dcbdf7124eb60 2012/10/29 00:06:37 30226 records - OK
anj0z54d 7.0 abaf5f7fda7308fcf7573b193bbf2116723e9802 2012/10/22 00:04:37 16441 records - OK
gwui2rez 7.0 5adc85528fb49e201d4bc61eca580d6839cc4a4c 2012/10/15 00:05:04 26289 records - OK
0vprby8u 7.0 da8cf3fbd81206bb3d8103347a439f920a74bbe2 2012/10/08 00:05:51 27278 records - OK
zjvv4nkf 7.0 5988744d3cb357f1a013427d466e2d79ab5f8907 2012/10/01 00:05:11 17444 records - OK
1a6npzry 7.0 d4a0dabf4a4df0f79805c6ccdc025f796765e786 2012/09/24 00:06:30 21205 records - OK
ds9p2oz8 7.0 82ed005784d9e258213070a0cd8bfceff345018d 2012/09/17 00:05:43 11686 records - OK
4zcbqyp1 7.0 a95ae63004b8d857c2db055f4e47c15bfc97f626 2012/09/10 00:04:34 12677 records - OK
7ns3swbz 7.0 c39bf233d25242ae9ed8cf204b9b788c8f45ab79 2012/09/03 00:05:28 10118 records - OK
o6kzqhca 7.0 d37b5484b009947b7cdd3837dafe8148615401c2 2012/08/27 00:05:26 12602 records - OK
ev7qacot 7.0 41bf1347794ab7060dec7aaecc1d1d95cf6fecb5 2012/08/20 00:04:05 18298 records - OK
p8170k1c 7.0 1a997511e5892aaeb69b3db70e06676af36382e3 2012/08/13 00:05:19 17126 records - OK
5wq3ye9m 7.0 f7226c59914e3683e538e668c3b664af3232654d 2012/08/06 00:03:53 20539 records - OK
led1tuz5 7.0 4035c8d3b617bf935a317a8c57efaa8e835a61f4 2012/07/30 00:05:26 19330 records - OK
g199agyn 7.0 09b55bc000f184ed426f1d8b9665669346fe5e71 2012/07/23 00:05:34 19692 records - OK
3koqhzlo 7.0 f746c097f298e94faa9db94e6f64ef9fd4a7b010 2012/07/16 00:05:43 14727 records - OK
g3e9zh4x 7.0 792a6a25a17e764390440cd4c2c6ca5a97ab162f 2012/07/09 00:04:33 19485 records - OK
7weid9p9 7.0 ca9905c39e3d93428a4db65a192debe9fbd7acf7 2012/07/02 00:04:55 22898 records - OK
6nb8jxh3 7.0 dc29c610b866c66ba5327e7830452b2460149a35 2012/06/25 00:05:17 20551 records - OK
vxqfkzdp 7.0 c28739bea153508d12942ac9a61abd475d0a0404 2012/06/18 00:03:35 9661 records - OK
a1u1av4f 7.0 e5b5835a7c512120c5348e31483a4caa2a845d28 2012/06/11 00:04:32 23632 records - OK
rv4chy08 7.0 61853ce89026ef0ebbd80174f1b7dd5d25bbc63a 2012/06/04 00:04:41 12423 records - OK
h7d6jvew 7.0 4e6c9897e153b47ca97b7da48ceed23e555a7761 2012/05/28 00:04:26 15493 records - OK
cw9jnmkx 7.0 35f4c105cecd8ec1fd01714abebf30f8f3efb96e 2012/05/21 00:03:29 13065 records - OK
p32ksc6v 7.0 3522aa84677411aa7d67796bb05ea3ab62f02a71 2012/05/14 00:04:24 16238 records - OK
tvaj5n1s 7.0 7597333540eda537bd42c0a17d4a6526ad247a2e 2012/05/07 00:04:33 11570 records - OK
pg8tpmq0 7.0 867814380363bc6ad605acf4b96e02c54dbd60f7 2012/04/30 00:03:28 15478 records - OK
q7q6x2qe 7.0 3c04f402d91a19039cb9c223c435dc4ea1bb3da4 2012/04/23 00:05:05 11881 records - OK
x1euc1zt 7.0 8d0220a2a50b367e61a51d3b29c2659cde41bb7f 2012/04/16 00:03:29 13578 records - OK
i3yfitb8 7.0 b79dc6f5832ad390108d1880694ec538e8b34bb0 2012/04/09 00:05:02 14292 records - OK
nn69b6li 7.0 8ff7cc095c43c2154275b7a54a89bf365e8daf4a 2012/04/02 00:03:24 14084 records - OK
ht42gtcz 7.0 9502a428b32be4ad08556134e271c9ba03195398 2012/03/26 00:04:43 19126 records - OK
6driea1s 7.0 28c2fabbc645aff41baac12b911a8499ea163536 2012/03/19 00:03:23 14920 records - OK
qzxkjvih 7.0 86de597ff06e58206f94263f2eef33cb41b2530c 2012/03/12 00:03:25 19017 records - OK
xmgylny0 7.0 5bd1d666e7c9ca70c34e591dc6c55314ce4b11af 2012/03/05 00:04:32 19691 records - OK
xjec35ie 7.0 15a9d10c451d2fcf124700f29f557d9bf338e671 2012/02/27 00:03:21 23605 records - OK
p0jd2yp6 7.0 5647d941e5358105ca6558dce78873f06c48d5dc 2012/02/20 00:03:45 19067 records - OK
6u83ljyw 7.0 c9b2600cb665ce34e0ccd0f19e0a88cd44437f51 2012/02/13 00:04:49 19019 records - OK
q21kau98 7.0 9df2e129e78a9d9ab491186da1329c1dd1190e17 2012/02/06 00:05:25 28028 records - OK
wwxa90cq 7.0 b69b9504a51b8777b8e95a4680dc8ac1d8d8c25d 2012/01/30 00:08:41 29444 records - OK
ronji74e 7.0 3d7431bdee1a22d6329e017f348db7760f2645ac 2012/01/23 05:22:13 19353 records - OK
noo3ddnb 7.0 e04570f78fb00d758abdf77c534a460980e102c0 2012/01/16 00:12:31 20747 records - OK
rihip9qa 7.0 2de2479b112c4416e2375343f57ca789b042aecc 2012/01/09 00:04:30 28052 records - OK
xq398x37 7.0 c4bd9612ff1f71d8bd23b4f1bc114eed1ae2ee6b 2012/01/02 00:04:40 12183 records - OK
x2dwz393 7.0 28b1d218ade8f05fdc8550c7456ac3b74f705208 2011/12/26 00:03:33 19984 records - OK
up75s1h1 7.0 539e41e8f3d97a6f347600c7cef903d9f34e0518 2011/12/19 00:08:45 22627 records - OK
jv995deh 7.0 f8e81968965f555bce0d02fc9933fee840b97aaf 2011/12/12 17:20:22 49580 records - OK
y5z5d8p9 7.0 14751e0f442bba3efc08ee12d82a2815c61cfeb6 2011/12/04 05:00:00 45195 records - OK
m4rd62nz 7.0 1a1e6cb9b3096a2cbba2c31d05e11914c0357d52 2011/12/04 04:00:00 165532 records - OK
fq1ts6lo 7.0 0f948a7d416c556bfc8a8be2c2c39f998fee6d9e 2011/12/04 03:00:00 170820 records - OK
udyjdtg5 7.0 9357c3cc73a4a374346a678f197daa22496c7ae5 2011/12/04 02:00:00 171279 records - OK
225azu94 7.0 ae56b06b3d6f1e13c5f10cce4ed68f2cccbf3298 2011/12/04 01:00:00 170253 records - OK
1puna13c 7.0 fdaab5c1079d02c94f20d07c39d638cad79d8771 2011/12/04 00:00:00 170291 records - OK
v8vh89wa 7.0 b59d8841e65d7670b2aae7f2b65734269f6c4fe3 2011/12/03 23:00:00 170501 records - OK
typjp0bg 7.0 3946b1d195434cf7a70d144da71c87559475c58f 2011/12/03 22:00:00 353582 records - OK
rj0d6ke2 7.0 8df4695f74ea5949551df6044720694e204b13d7 2011/12/03 21:00:00 852776 records - OK
cc0embkz 7.0 5580fd78c8614641102fa37faf015524b5e02ea3 2013/07/01 07:41:00 1351 records - OK
ds1fbxkr 7.0 0cb77ee7a3e6545553585eb6df267a86d4fecbe4 2013/04/22 00:14:29 1680 records - OK
n60u01nh 7.0 6cb68b8fab821702ef054f864ff44917414e50fa 2013/02/04 00:13:43 2078 records - OK
n1kn668y 7.0 cfbe9cf43615f7856e4c35f0fc02e2baf12e39e7 2012/12/17 00:14:14 1725 records - OK
alhtvn2b 7.0 047694e79b1a8d295f27ea9c6565062404f84a57 2012/11/12 00:12:52 2050 records - OK
4g0sve0v 7.0 f3413603f4ee1c88018a78c1f6faf2abeb8fa8c1 2012/09/24 00:13:14 1456 records - OK
rvdy5sp4 7.0 8871f579eeb7e5e7b70c6dd898afd27391d7daf4 2012/06/25 00:12:36 1421 records - OK
se2ec0og 7.0 3ee43130fe7fec4b367a791892a444d0a791b29b 2012/03/26 00:12:30 1385 records - OK
y0cquuv0 7.0 fddc5d687537580c7166dbf117d591593bc62261 2012/01/23 01:56:09 1653 records - OK
44t6ofg8 7.0 47656cca26f2beec5fd8105cabfd7f5e8aba8e56 2013/07/01 07:40:52 956 records - OK
8mg524fh 7.0 45cdfad530697916adbfea43a8763a4ab0c95beb 2013/05/20 00:24:48 1426 records - OK
0kof117d 7.0 bd9fd948b79e07c8676018e17a43ee81f5335e36 2013/04/22 00:24:10 1641 records - OK
zguj26jj 7.0 c7f70566b9bae9fd3f5a8d0b56d961f890a55508 2013/03/18 00:23:44 1742 records - OK
k4uekspg 7.0 8893c0d254eb40c78b5c78ea17fbc3be60ea6304 2013/01/21 00:24:33 2016 records - OK
2ni6n45v 7.0 cdf3a9d2dcab57f90c378d9eefacbfd358a42699 2012/12/10 00:23:23 1620 records - OK
ppgxxxg8 7.0 c0726ba000e840272f0810b89051e6daa8799084 2012/11/05 00:23:16 1658 records - OK
bhv54x9n 7.0 216611859de0125bf130d6324d43c9115cb05def 2012/10/08 00:23:20 1465 records - OK
za3wt3r7 7.0 264c14ad60c4423ec292f5f8b182e4448504dfa9 2012/09/10 00:23:14 1588 records - OK
t5tbduu1 7.0 33197bfe9efefa9db33725d240757103c625b601 2012/07/23 00:22:36 1702 records - OK
0o355j0u 7.0 74d8e114edb84b95bc09d5a2a36191d15a61e2cb 2012/06/11 00:22:36 1659 records - OK
xhbw8qg6 7.0 79ca8239f310688d2b9c314fa3d738a34985cce3 2012/04/30 00:22:34 1670 records - OK
5o25y8h5 7.0 aac27e986e3731e5260cb76f5b14558e36660dec 2012/03/12 00:22:28 1729 records - OK
cwb7nkkr 7.0 fa5c96b8be693a20c2a295e3545419e6f117fdc4 2012/01/30 00:23:00 1523 records - OK
9r23485v 7.0 e9b21e0a3578ef2e2067f4876309671ddc78f65f 2011/12/19 00:22:29 1805 records - OK
nphz51gk 7.0 8f7a8f6f55130f6becc5331ab38dc2108746b8aa 2011/12/03 20:00:00 26456 records - OK
s2ts4avm 7.0 e6d52b11d2f7d405ccd31347da3b6fde69825168 2011/12/03 19:00:00 74279 records - OK
3t4zqwg8 7.0 e20ffde4bbc58e0585b0b3b2f324bc91272c2360 2011/12/03 18:00:00 1 record - OK
Total records count: 4174588
Anti-rootkit module version ( ver: 8.3.201306200, api: 5.01/5.01 )
 
Using C:\Users\Johnson\AppData\Local\Temp\6E18E884-EEE270E8-8093A2D0-9B2726D0\12jlmmz8.key as Dr.Web ® Key file
This Dr.Web ® Key is for 1 computer (A User)
=============================================================================
Dr.Web Scanner SE for Windows v8.2.0.05230
© Doctor Web, Ltd., 1992-2013
Scan session started 2013/07/01 10:53:02 
Module location : C:\Users\Johnson\AppData\Local\Temp\FDE479E-3856037A-FFD59BDA-D3FE34FC\
=============================================================================
OPTION [Automatic Apply Actions] NO
OPTION [Turn Off Computer After Scan] NO
OPTION [Use Sound Alerts] NO
OPTION [Block Network] NO
OPTION [Protect Process] NO
OPTION [Protect Raw Disk] NO
Using language: "English"
Available instances: 12
Instances used: 12
Platform: Windows 8 Starter x64/WOW (Build 9200)
API Version: 2.2
Scanning Engine version: 8.1.0.6170
Virus Finding Engine version: 7.0.4.9250
Total 121 virus bases are loaded from C:\Users\Johnson\AppData\Local\Temp\FDE479E-3856037A-FFD59BDA-D3FE34FC
07pa931w 7.0 bbe7c7b3a3c63ab0d27ae3cfc621a6d49b740e48 2013/07/01 07:40:33 1822 records - OK
gau5b2hq 7.0 215c2d42a54f5188e8159bfd122292450d16f29b 2011/07/25 11:20:03 2 records - OK
az83p58q 7.0 fa04678f170a21ec39077750c8424cfc0f225584 2013/07/01 00:08:41 1 record - OK
laqgny4d 7.0 613a3e4bae38b4e00a7432c24a9cd916fb1c654f 2013/07/01 00:06:34 24654 records - OK
gfivwji6 7.0 b81132c4abffd4d2949531a1219b6bb1c3bad6f7 2013/06/24 00:06:30 14062 records - OK
ua5ygcla 7.0 9aab251475626c658b193cfa2b5f91da471bf8f2 2013/06/17 00:05:57 13350 records - OK
vl6x1jg7 7.0 e1f8aca88745fcdd49dc7ae75e142c41e1faf178 2013/06/10 00:08:13 26371 records - OK
2rg5c02s 7.0 4e8627555a073f6bad5218bad3e69ebc4b93069f 2013/06/03 00:07:47 25525 records - OK
msdlbumv 7.0 f562371c5115143824efde38c9567c34ccbe5d1a 2013/05/27 00:16:19 33200 records - OK
u8a8ygx7 7.0 eccb30ec8ed44456f9b88fe96d9fe0de40e4fa51 2013/05/20 00:11:05 46384 records - OK
ftxh022j 7.0 9b481fbfbe1f564a84f21552da1d30d24e7b01db 2013/05/13 00:07:01 34270 records - OK
xhx25x5h 7.0 1bf754dd720727b5d6803e081c16ff7f4ba7b40b 2013/05/06 00:08:46 41611 records - OK
5fec29vr 7.0 4e883c92513c2d991968fb3e4f27910a63d9a2df 2013/04/29 00:06:36 36105 records - OK
v4gwq06e 7.0 b047d178295ecde53c3cf1c34e4361004569fa33 2013/04/22 00:07:26 31319 records - OK
fknk2ga0 7.0 9207e55a924e4aa989dfde4d8d219cf5cc200ce2 2013/04/15 00:07:56 28216 records - OK
4t8q6jl1 7.0 78855cfb9fbc063889c5405a577fe73188f08789 2013/04/08 00:05:35 23589 records - OK
lkr3hq0s 7.0 cec6d34c79d50608520e81b90a23d91f39df0b27 2013/04/01 00:07:37 26946 records - OK
af9yisir 7.0 fd3c78d78ea4dae4e252a7f7d76db22e1a679be9 2013/03/25 00:05:37 34778 records - OK
bcx8r9ze 7.0 268e71b1123ab5e60fd2f38d269fe5f3d22b3697 2013/03/18 00:06:19 11271 records - OK
m2mbvyvh 7.0 d196879775b0dc0ee8286f2e4def9adedb5b88df 2013/03/11 00:05:36 12046 records - OK
9tfyxh22 7.0 0db61d4e3235481da8493523538ced712db362c2 2013/03/04 00:05:18 21747 records - OK
ojdqayb8 7.0 65f99faf227b51883c9f1c854a3f76806b60affb 2013/02/25 00:06:28 11540 records - OK
dsysogkk 7.0 17bd7383b9c4b214c5c9029171db8ae1455984a0 2013/02/18 00:06:38 15568 records - OK
m8wgshci 7.0 cbe8774953ae403e49370d552b522a5839aa9fdb 2013/02/11 00:06:00 18805 records - OK
zaat1f62 7.0 fb6865c02a3680338e4ee0603579107227313b2b 2013/02/04 00:06:01 32488 records - OK
2ixpn8mc 7.0 95fcd2e24cd9b2ec2610656ffa70b8bf46e86a8b 2013/01/28 00:04:52 15470 records - OK
of94ow0h 7.0 3d710b3dd4580a7eca8c74d2c886d48f5b8b5172 2013/01/21 00:06:27 30093 records - OK
1xiaa9gg 7.0 bddde0b5426b7e5bebd61e1239ca529c87ae6e36 2013/01/14 00:04:41 16158 records - OK
lg84572c 7.0 bc40bd9330301e8d7796f489d03357fb711b3121 2013/01/07 00:04:45 19597 records - OK
9dvofzbx 7.0 805b6089c867549c75f843eac96b759c3f8d101f 2012/12/31 00:05:41 18184 records - OK
oty7up69 7.0 c12a817c1f95bb9fd8238ef0d5f68868a8d95686 2012/12/24 00:05:33 30183 records - OK
8fj474fk 7.0 33def496782eb5b7b1cc93fdb036a1b62fa6a2fd 2012/12/17 00:06:21 25519 records - OK
tqcfcpxt 7.0 422abae03c588822f412aa9aae50578a1d61737e 2012/12/10 00:05:04 20358 records - OK
6qvtl81v 7.0 a4f0d0ecad4fb6e0afdb1925f4e0b7863b9d03fa 2012/12/03 00:06:19 20133 records - OK
5cv2ct20 7.0 86daa918ee3de1e4c1e5dea6f9b5f63544cf8814 2012/11/26 00:05:22 27311 records - OK
ukc4wq20 7.0 6556881c748e1f894eb9c7943ebae67017e1aec2 2012/11/19 00:06:09 29434 records - OK
a4r65qh2 7.0 559141ef34f9e6226bb58560e9b52e4cc5165150 2012/11/12 00:06:22 26900 records - OK
5g3f4awx 7.0 cc55013e63ff89319ec772e34d77056c7108cd3b 2012/11/05 00:05:22 25164 records - OK
pjy4858c 7.0 f477dc247d9b562bb64fd4f46a7dcbdf7124eb60 2012/10/29 00:06:37 30226 records - OK
anj0z54d 7.0 abaf5f7fda7308fcf7573b193bbf2116723e9802 2012/10/22 00:04:37 16441 records - OK
gwui2rez 7.0 5adc85528fb49e201d4bc61eca580d6839cc4a4c 2012/10/15 00:05:04 26289 records - OK
0vprby8u 7.0 da8cf3fbd81206bb3d8103347a439f920a74bbe2 2012/10/08 00:05:51 27278 records - OK
zjvv4nkf 7.0 5988744d3cb357f1a013427d466e2d79ab5f8907 2012/10/01 00:05:11 17444 records - OK
1a6npzry 7.0 d4a0dabf4a4df0f79805c6ccdc025f796765e786 2012/09/24 00:06:30 21205 records - OK
ds9p2oz8 7.0 82ed005784d9e258213070a0cd8bfceff345018d 2012/09/17 00:05:43 11686 records - OK
4zcbqyp1 7.0 a95ae63004b8d857c2db055f4e47c15bfc97f626 2012/09/10 00:04:34 12677 records - OK
7ns3swbz 7.0 c39bf233d25242ae9ed8cf204b9b788c8f45ab79 2012/09/03 00:05:28 10118 records - OK
o6kzqhca 7.0 d37b5484b009947b7cdd3837dafe8148615401c2 2012/08/27 00:05:26 12602 records - OK
ev7qacot 7.0 41bf1347794ab7060dec7aaecc1d1d95cf6fecb5 2012/08/20 00:04:05 18298 records - OK
p8170k1c 7.0 1a997511e5892aaeb69b3db70e06676af36382e3 2012/08/13 00:05:19 17126 records - OK
5wq3ye9m 7.0 f7226c59914e3683e538e668c3b664af3232654d 2012/08/06 00:03:53 20539 records - OK
led1tuz5 7.0 4035c8d3b617bf935a317a8c57efaa8e835a61f4 2012/07/30 00:05:26 19330 records - OK
g199agyn 7.0 09b55bc000f184ed426f1d8b9665669346fe5e71 2012/07/23 00:05:34 19692 records - OK
3koqhzlo 7.0 f746c097f298e94faa9db94e6f64ef9fd4a7b010 2012/07/16 00:05:43 14727 records - OK
g3e9zh4x 7.0 792a6a25a17e764390440cd4c2c6ca5a97ab162f 2012/07/09 00:04:33 19485 records - OK
7weid9p9 7.0 ca9905c39e3d93428a4db65a192debe9fbd7acf7 2012/07/02 00:04:55 22898 records - OK
6nb8jxh3 7.0 dc29c610b866c66ba5327e7830452b2460149a35 2012/06/25 00:05:17 20551 records - OK
vxqfkzdp 7.0 c28739bea153508d12942ac9a61abd475d0a0404 2012/06/18 00:03:35 9661 records - OK
a1u1av4f 7.0 e5b5835a7c512120c5348e31483a4caa2a845d28 2012/06/11 00:04:32 23632 records - OK
rv4chy08 7.0 61853ce89026ef0ebbd80174f1b7dd5d25bbc63a 2012/06/04 00:04:41 12423 records - OK
h7d6jvew 7.0 4e6c9897e153b47ca97b7da48ceed23e555a7761 2012/05/28 00:04:26 15493 records - OK
cw9jnmkx 7.0 35f4c105cecd8ec1fd01714abebf30f8f3efb96e 2012/05/21 00:03:29 13065 records - OK
p32ksc6v 7.0 3522aa84677411aa7d67796bb05ea3ab62f02a71 2012/05/14 00:04:24 16238 records - OK
tvaj5n1s 7.0 7597333540eda537bd42c0a17d4a6526ad247a2e 2012/05/07 00:04:33 11570 records - OK
pg8tpmq0 7.0 867814380363bc6ad605acf4b96e02c54dbd60f7 2012/04/30 00:03:28 15478 records - OK
q7q6x2qe 7.0 3c04f402d91a19039cb9c223c435dc4ea1bb3da4 2012/04/23 00:05:05 11881 records - OK
x1euc1zt 7.0 8d0220a2a50b367e61a51d3b29c2659cde41bb7f 2012/04/16 00:03:29 13578 records - OK
i3yfitb8 7.0 b79dc6f5832ad390108d1880694ec538e8b34bb0 2012/04/09 00:05:02 14292 records - OK
nn69b6li 7.0 8ff7cc095c43c2154275b7a54a89bf365e8daf4a 2012/04/02 00:03:24 14084 records - OK
ht42gtcz 7.0 9502a428b32be4ad08556134e271c9ba03195398 2012/03/26 00:04:43 19126 records - OK
6driea1s 7.0 28c2fabbc645aff41baac12b911a8499ea163536 2012/03/19 00:03:23 14920 records - OK
qzxkjvih 7.0 86de597ff06e58206f94263f2eef33cb41b2530c 2012/03/12 00:03:25 19017 records - OK
xmgylny0 7.0 5bd1d666e7c9ca70c34e591dc6c55314ce4b11af 2012/03/05 00:04:32 19691 records - OK
xjec35ie 7.0 15a9d10c451d2fcf124700f29f557d9bf338e671 2012/02/27 00:03:21 23605 records - OK
p0jd2yp6 7.0 5647d941e5358105ca6558dce78873f06c48d5dc 2012/02/20 00:03:45 19067 records - OK
6u83ljyw 7.0 c9b2600cb665ce34e0ccd0f19e0a88cd44437f51 2012/02/13 00:04:49 19019 records - OK
q21kau98 7.0 9df2e129e78a9d9ab491186da1329c1dd1190e17 2012/02/06 00:05:25 28028 records - OK
wwxa90cq 7.0 b69b9504a51b8777b8e95a4680dc8ac1d8d8c25d 2012/01/30 00:08:41 29444 records - OK
ronji74e 7.0 3d7431bdee1a22d6329e017f348db7760f2645ac 2012/01/23 05:22:13 19353 records - OK
noo3ddnb 7.0 e04570f78fb00d758abdf77c534a460980e102c0 2012/01/16 00:12:31 20747 records - OK
rihip9qa 7.0 2de2479b112c4416e2375343f57ca789b042aecc 2012/01/09 00:04:30 28052 records - OK
xq398x37 7.0 c4bd9612ff1f71d8bd23b4f1bc114eed1ae2ee6b 2012/01/02 00:04:40 12183 records - OK
x2dwz393 7.0 28b1d218ade8f05fdc8550c7456ac3b74f705208 2011/12/26 00:03:33 19984 records - OK
up75s1h1 7.0 539e41e8f3d97a6f347600c7cef903d9f34e0518 2011/12/19 00:08:45 22627 records - OK
jv995deh 7.0 f8e81968965f555bce0d02fc9933fee840b97aaf 2011/12/12 17:20:22 49580 records - OK
y5z5d8p9 7.0 14751e0f442bba3efc08ee12d82a2815c61cfeb6 2011/12/04 05:00:00 45195 records - OK
m4rd62nz 7.0 1a1e6cb9b3096a2cbba2c31d05e11914c0357d52 2011/12/04 04:00:00 165532 records - OK
fq1ts6lo 7.0 0f948a7d416c556bfc8a8be2c2c39f998fee6d9e 2011/12/04 03:00:00 170820 records - OK
udyjdtg5 7.0 9357c3cc73a4a374346a678f197daa22496c7ae5 2011/12/04 02:00:00 171279 records - OK
225azu94 7.0 ae56b06b3d6f1e13c5f10cce4ed68f2cccbf3298 2011/12/04 01:00:00 170253 records - OK
1puna13c 7.0 fdaab5c1079d02c94f20d07c39d638cad79d8771 2011/12/04 00:00:00 170291 records - OK
v8vh89wa 7.0 b59d8841e65d7670b2aae7f2b65734269f6c4fe3 2011/12/03 23:00:00 170501 records - OK
typjp0bg 7.0 3946b1d195434cf7a70d144da71c87559475c58f 2011/12/03 22:00:00 353582 records - OK
rj0d6ke2 7.0 8df4695f74ea5949551df6044720694e204b13d7 2011/12/03 21:00:00 852776 records - OK
cc0embkz 7.0 5580fd78c8614641102fa37faf015524b5e02ea3 2013/07/01 07:41:00 1351 records - OK
ds1fbxkr 7.0 0cb77ee7a3e6545553585eb6df267a86d4fecbe4 2013/04/22 00:14:29 1680 records - OK
n60u01nh 7.0 6cb68b8fab821702ef054f864ff44917414e50fa 2013/02/04 00:13:43 2078 records - OK
n1kn668y 7.0 cfbe9cf43615f7856e4c35f0fc02e2baf12e39e7 2012/12/17 00:14:14 1725 records - OK
alhtvn2b 7.0 047694e79b1a8d295f27ea9c6565062404f84a57 2012/11/12 00:12:52 2050 records - OK
4g0sve0v 7.0 f3413603f4ee1c88018a78c1f6faf2abeb8fa8c1 2012/09/24 00:13:14 1456 records - OK
rvdy5sp4 7.0 8871f579eeb7e5e7b70c6dd898afd27391d7daf4 2012/06/25 00:12:36 1421 records - OK
se2ec0og 7.0 3ee43130fe7fec4b367a791892a444d0a791b29b 2012/03/26 00:12:30 1385 records - OK
y0cquuv0 7.0 fddc5d687537580c7166dbf117d591593bc62261 2012/01/23 01:56:09 1653 records - OK
44t6ofg8 7.0 47656cca26f2beec5fd8105cabfd7f5e8aba8e56 2013/07/01 07:40:52 956 records - OK
8mg524fh 7.0 45cdfad530697916adbfea43a8763a4ab0c95beb 2013/05/20 00:24:48 1426 records - OK
0kof117d 7.0 bd9fd948b79e07c8676018e17a43ee81f5335e36 2013/04/22 00:24:10 1641 records - OK
zguj26jj 7.0 c7f70566b9bae9fd3f5a8d0b56d961f890a55508 2013/03/18 00:23:44 1742 records - OK
k4uekspg 7.0 8893c0d254eb40c78b5c78ea17fbc3be60ea6304 2013/01/21 00:24:33 2016 records - OK
2ni6n45v 7.0 cdf3a9d2dcab57f90c378d9eefacbfd358a42699 2012/12/10 00:23:23 1620 records - OK
ppgxxxg8 7.0 c0726ba000e840272f0810b89051e6daa8799084 2012/11/05 00:23:16 1658 records - OK
bhv54x9n 7.0 216611859de0125bf130d6324d43c9115cb05def 2012/10/08 00:23:20 1465 records - OK
za3wt3r7 7.0 264c14ad60c4423ec292f5f8b182e4448504dfa9 2012/09/10 00:23:14 1588 records - OK
t5tbduu1 7.0 33197bfe9efefa9db33725d240757103c625b601 2012/07/23 00:22:36 1702 records - OK
0o355j0u 7.0 74d8e114edb84b95bc09d5a2a36191d15a61e2cb 2012/06/11 00:22:36 1659 records - OK
xhbw8qg6 7.0 79ca8239f310688d2b9c314fa3d738a34985cce3 2012/04/30 00:22:34 1670 records - OK
5o25y8h5 7.0 aac27e986e3731e5260cb76f5b14558e36660dec 2012/03/12 00:22:28 1729 records - OK
cwb7nkkr 7.0 fa5c96b8be693a20c2a295e3545419e6f117fdc4 2012/01/30 00:23:00 1523 records - OK
9r23485v 7.0 e9b21e0a3578ef2e2067f4876309671ddc78f65f 2011/12/19 00:22:29 1805 records - OK
nphz51gk 7.0 8f7a8f6f55130f6becc5331ab38dc2108746b8aa 2011/12/03 20:00:00 26456 records - OK
s2ts4avm 7.0 e6d52b11d2f7d405ccd31347da3b6fde69825168 2011/12/03 19:00:00 74279 records - OK
3t4zqwg8 7.0 e20ffde4bbc58e0585b0b3b2f324bc91272c2360 2011/12/03 18:00:00 1 record - OK
Total records count: 4174588
Anti-rootkit module version ( ver: 8.3.201306200, api: 5.01/5.01 )
 
Using C:\Users\Johnson\AppData\Local\Temp\FDE479E-3856037A-FFD59BDA-D3FE34FC\12jlmmz8.key as Dr.Web ® Key file
This Dr.Web ® Key is for 1 computer (A User)
=============================================================================
Dr.Web Scanner SE for Windows v8.2.0.05230
© Doctor Web, Ltd., 1992-2013
Scan session started 2013/07/01 10:53:37 
Module location : C:\Users\Johnson\AppData\Local\Temp\75E8A834-955F53D8-1AE65180-2B2DD838\
=============================================================================
OPTION [Automatic Apply Actions] NO
OPTION [Turn Off Computer After Scan] NO
OPTION [Use Sound Alerts] NO
OPTION [Block Network] NO
OPTION [Protect Process] NO
OPTION [Protect Raw Disk] NO
Using language: "English"
Change language: "Portuguese (Português)"
Available instances: 12
Instances used: 12
Platform: Windows 8 Starter x64/WOW (Build 9200)
API Version: 2.2
Scanning Engine version: 8.1.0.6170
Virus Finding Engine version: 7.0.4.9250
Total 121 virus bases are loaded from C:\Users\Johnson\AppData\Local\Temp\75E8A834-955F53D8-1AE65180-2B2DD838
07pa931w 7.0 bbe7c7b3a3c63ab0d27ae3cfc621a6d49b740e48 2013/07/01 07:40:33 1822 records - OK
gau5b2hq 7.0 215c2d42a54f5188e8159bfd122292450d16f29b 2011/07/25 11:20:03 2 records - OK
az83p58q 7.0 fa04678f170a21ec39077750c8424cfc0f225584 2013/07/01 00:08:41 1 record - OK
laqgny4d 7.0 613a3e4bae38b4e00a7432c24a9cd916fb1c654f 2013/07/01 00:06:34 24654 records - OK
gfivwji6 7.0 b81132c4abffd4d2949531a1219b6bb1c3bad6f7 2013/06/24 00:06:30 14062 records - OK
ua5ygcla 7.0 9aab251475626c658b193cfa2b5f91da471bf8f2 2013/06/17 00:05:57 13350 records - OK
vl6x1jg7 7.0 e1f8aca88745fcdd49dc7ae75e142c41e1faf178 2013/06/10 00:08:13 26371 records - OK
2rg5c02s 7.0 4e8627555a073f6bad5218bad3e69ebc4b93069f 2013/06/03 00:07:47 25525 records - OK
msdlbumv 7.0 f562371c5115143824efde38c9567c34ccbe5d1a 2013/05/27 00:16:19 33200 records - OK
u8a8ygx7 7.0 eccb30ec8ed44456f9b88fe96d9fe0de40e4fa51 2013/05/20 00:11:05 46384 records - OK
ftxh022j 7.0 9b481fbfbe1f564a84f21552da1d30d24e7b01db 2013/05/13 00:07:01 34270 records - OK
xhx25x5h 7.0 1bf754dd720727b5d6803e081c16ff7f4ba7b40b 2013/05/06 00:08:46 41611 records - OK
5fec29vr 7.0 4e883c92513c2d991968fb3e4f27910a63d9a2df 2013/04/29 00:06:36 36105 records - OK
v4gwq06e 7.0 b047d178295ecde53c3cf1c34e4361004569fa33 2013/04/22 00:07:26 31319 records - OK
fknk2ga0 7.0 9207e55a924e4aa989dfde4d8d219cf5cc200ce2 2013/04/15 00:07:56 28216 records - OK
4t8q6jl1 7.0 78855cfb9fbc063889c5405a577fe73188f08789 2013/04/08 00:05:35 23589 records - OK
lkr3hq0s 7.0 cec6d34c79d50608520e81b90a23d91f39df0b27 2013/04/01 00:07:37 26946 records - OK
af9yisir 7.0 fd3c78d78ea4dae4e252a7f7d76db22e1a679be9 2013/03/25 00:05:37 34778 records - OK
bcx8r9ze 7.0 268e71b1123ab5e60fd2f38d269fe5f3d22b3697 2013/03/18 00:06:19 11271 records - OK
m2mbvyvh 7.0 d196879775b0dc0ee8286f2e4def9adedb5b88df 2013/03/11 00:05:36 12046 records - OK
9tfyxh22 7.0 0db61d4e3235481da8493523538ced712db362c2 2013/03/04 00:05:18 21747 records - OK
ojdqayb8 7.0 65f99faf227b51883c9f1c854a3f76806b60affb 2013/02/25 00:06:28 11540 records - OK
dsysogkk 7.0 17bd7383b9c4b214c5c9029171db8ae1455984a0 2013/02/18 00:06:38 15568 records - OK
m8wgshci 7.0 cbe8774953ae403e49370d552b522a5839aa9fdb 2013/02/11 00:06:00 18805 records - OK
zaat1f62 7.0 fb6865c02a3680338e4ee0603579107227313b2b 2013/02/04 00:06:01 32488 records - OK
2ixpn8mc 7.0 95fcd2e24cd9b2ec2610656ffa70b8bf46e86a8b 2013/01/28 00:04:52 15470 records - OK
of94ow0h 7.0 3d710b3dd4580a7eca8c74d2c886d48f5b8b5172 2013/01/21 00:06:27 30093 records - OK
1xiaa9gg 7.0 bddde0b5426b7e5bebd61e1239ca529c87ae6e36 2013/01/14 00:04:41 16158 records - OK
lg84572c 7.0 bc40bd9330301e8d7796f489d03357fb711b3121 2013/01/07 00:04:45 19597 records - OK
9dvofzbx 7.0 805b6089c867549c75f843eac96b759c3f8d101f 2012/12/31 00:05:41 18184 records - OK
oty7up69 7.0 c12a817c1f95bb9fd8238ef0d5f68868a8d95686 2012/12/24 00:05:33 30183 records - OK
8fj474fk 7.0 33def496782eb5b7b1cc93fdb036a1b62fa6a2fd 2012/12/17 00:06:21 25519 records - OK
tqcfcpxt 7.0 422abae03c588822f412aa9aae50578a1d61737e 2012/12/10 00:05:04 20358 records - OK
6qvtl81v 7.0 a4f0d0ecad4fb6e0afdb1925f4e0b7863b9d03fa 2012/12/03 00:06:19 20133 records - OK
5cv2ct20 7.0 86daa918ee3de1e4c1e5dea6f9b5f63544cf8814 2012/11/26 00:05:22 27311 records - OK
ukc4wq20 7.0 6556881c748e1f894eb9c7943ebae67017e1aec2 2012/11/19 00:06:09 29434 records - OK
a4r65qh2 7.0 559141ef34f9e6226bb58560e9b52e4cc5165150 2012/11/12 00:06:22 26900 records - OK
5g3f4awx 7.0 cc55013e63ff89319ec772e34d77056c7108cd3b 2012/11/05 00:05:22 25164 records - OK
pjy4858c 7.0 f477dc247d9b562bb64fd4f46a7dcbdf7124eb60 2012/10/29 00:06:37 30226 records - OK
anj0z54d 7.0 abaf5f7fda7308fcf7573b193bbf2116723e9802 2012/10/22 00:04:37 16441 records - OK
gwui2rez 7.0 5adc85528fb49e201d4bc61eca580d6839cc4a4c 2012/10/15 00:05:04 26289 records - OK
0vprby8u 7.0 da8cf3fbd81206bb3d8103347a439f920a74bbe2 2012/10/08 00:05:51 27278 records - OK
zjvv4nkf 7.0 5988744d3cb357f1a013427d466e2d79ab5f8907 2012/10/01 00:05:11 17444 records - OK
1a6npzry 7.0 d4a0dabf4a4df0f79805c6ccdc025f796765e786 2012/09/24 00:06:30 21205 records - OK
ds9p2oz8 7.0 82ed005784d9e258213070a0cd8bfceff345018d 2012/09/17 00:05:43 11686 records - OK
4zcbqyp1 7.0 a95ae63004b8d857c2db055f4e47c15bfc97f626 2012/09/10 00:04:34 12677 records - OK
7ns3swbz 7.0 c39bf233d25242ae9ed8cf204b9b788c8f45ab79 2012/09/03 00:05:28 10118 records - OK
o6kzqhca 7.0 d37b5484b009947b7cdd3837dafe8148615401c2 2012/08/27 00:05:26 12602 records - OK
ev7qacot 7.0 41bf1347794ab7060dec7aaecc1d1d95cf6fecb5 2012/08/20 00:04:05 18298 records - OK
p8170k1c 7.0 1a997511e5892aaeb69b3db70e06676af36382e3 2012/08/13 00:05:19 17126 records - OK
5wq3ye9m 7.0 f7226c59914e3683e538e668c3b664af3232654d 2012/08/06 00:03:53 20539 records - OK
led1tuz5 7.0 4035c8d3b617bf935a317a8c57efaa8e835a61f4 2012/07/30 00:05:26 19330 records - OK
g199agyn 7.0 09b55bc000f184ed426f1d8b9665669346fe5e71 2012/07/23 00:05:34 19692 records - OK
3koqhzlo 7.0 f746c097f298e94faa9db94e6f64ef9fd4a7b010 2012/07/16 00:05:43 14727 records - OK
g3e9zh4x 7.0 792a6a25a17e764390440cd4c2c6ca5a97ab162f 2012/07/09 00:04:33 19485 records - OK
7weid9p9 7.0 ca9905c39e3d93428a4db65a192debe9fbd7acf7 2012/07/02 00:04:55 22898 records - OK
6nb8jxh3 7.0 dc29c610b866c66ba5327e7830452b2460149a35 2012/06/25 00:05:17 20551 records - OK
vxqfkzdp 7.0 c28739bea153508d12942ac9a61abd475d0a0404 2012/06/18 00:03:35 9661 records - OK
a1u1av4f 7.0 e5b5835a7c512120c5348e31483a4caa2a845d28 2012/06/11 00:04:32 23632 records - OK
rv4chy08 7.0 61853ce89026ef0ebbd80174f1b7dd5d25bbc63a 2012/06/04 00:04:41 12423 records - OK
h7d6jvew 7.0 4e6c9897e153b47ca97b7da48ceed23e555a7761 2012/05/28 00:04:26 15493 records - OK
cw9jnmkx 7.0 35f4c105cecd8ec1fd01714abebf30f8f3efb96e 2012/05/21 00:03:29 13065 records - OK
p32ksc6v 7.0 3522aa84677411aa7d67796bb05ea3ab62f02a71 2012/05/14 00:04:24 16238 records - OK
tvaj5n1s 7.0 7597333540eda537bd42c0a17d4a6526ad247a2e 2012/05/07 00:04:33 11570 records - OK
pg8tpmq0 7.0 867814380363bc6ad605acf4b96e02c54dbd60f7 2012/04/30 00:03:28 15478 records - OK
q7q6x2qe 7.0 3c04f402d91a19039cb9c223c435dc4ea1bb3da4 2012/04/23 00:05:05 11881 records - OK
x1euc1zt 7.0 8d0220a2a50b367e61a51d3b29c2659cde41bb7f 2012/04/16 00:03:29 13578 records - OK
i3yfitb8 7.0 b79dc6f5832ad390108d1880694ec538e8b34bb0 2012/04/09 00:05:02 14292 records - OK
nn69b6li 7.0 8ff7cc095c43c2154275b7a54a89bf365e8daf4a 2012/04/02 00:03:24 14084 records - OK
ht42gtcz 7.0 9502a428b32be4ad08556134e271c9ba03195398 2012/03/26 00:04:43 19126 records - OK
6driea1s 7.0 28c2fabbc645aff41baac12b911a8499ea163536 2012/03/19 00:03:23 14920 records - OK
qzxkjvih 7.0 86de597ff06e58206f94263f2eef33cb41b2530c 2012/03/12 00:03:25 19017 records - OK
xmgylny0 7.0 5bd1d666e7c9ca70c34e591dc6c55314ce4b11af 2012/03/05 00:04:32 19691 records - OK
xjec35ie 7.0 15a9d10c451d2fcf124700f29f557d9bf338e671 2012/02/27 00:03:21 23605 records - OK
p0jd2yp6 7.0 5647d941e5358105ca6558dce78873f06c48d5dc 2012/02/20 00:03:45 19067 records - OK
6u83ljyw 7.0 c9b2600cb665ce34e0ccd0f19e0a88cd44437f51 2012/02/13 00:04:49 19019 records - OK
q21kau98 7.0 9df2e129e78a9d9ab491186da1329c1dd1190e17 2012/02/06 00:05:25 28028 records - OK
wwxa90cq 7.0 b69b9504a51b8777b8e95a4680dc8ac1d8d8c25d 2012/01/30 00:08:41 29444 records - OK
ronji74e 7.0 3d7431bdee1a22d6329e017f348db7760f2645ac 2012/01/23 05:22:13 19353 records - OK
noo3ddnb 7.0 e04570f78fb00d758abdf77c534a460980e102c0 2012/01/16 00:12:31 20747 records - OK
rihip9qa 7.0 2de2479b112c4416e2375343f57ca789b042aecc 2012/01/09 00:04:30 28052 records - OK
xq398x37 7.0 c4bd9612ff1f71d8bd23b4f1bc114eed1ae2ee6b 2012/01/02 00:04:40 12183 records - OK
x2dwz393 7.0 28b1d218ade8f05fdc8550c7456ac3b74f705208 2011/12/26 00:03:33 19984 records - OK
up75s1h1 7.0 539e41e8f3d97a6f347600c7cef903d9f34e0518 2011/12/19 00:08:45 22627 records - OK
jv995deh 7.0 f8e81968965f555bce0d02fc9933fee840b97aaf 2011/12/12 17:20:22 49580 records - OK
y5z5d8p9 7.0 14751e0f442bba3efc08ee12d82a2815c61cfeb6 2011/12/04 05:00:00 45195 records - OK
m4rd62nz 7.0 1a1e6cb9b3096a2cbba2c31d05e11914c0357d52 2011/12/04 04:00:00 165532 records - OK
fq1ts6lo 7.0 0f948a7d416c556bfc8a8be2c2c39f998fee6d9e 2011/12/04 03:00:00 170820 records - OK
udyjdtg5 7.0 9357c3cc73a4a374346a678f197daa22496c7ae5 2011/12/04 02:00:00 171279 records - OK
225azu94 7.0 ae56b06b3d6f1e13c5f10cce4ed68f2cccbf3298 2011/12/04 01:00:00 170253 records - OK
1puna13c 7.0 fdaab5c1079d02c94f20d07c39d638cad79d8771 2011/12/04 00:00:00 170291 records - OK
v8vh89wa 7.0 b59d8841e65d7670b2aae7f2b65734269f6c4fe3 2011/12/03 23:00:00 170501 records - OK
typjp0bg 7.0 3946b1d195434cf7a70d144da71c87559475c58f 2011/12/03 22:00:00 353582 records - OK
rj0d6ke2 7.0 8df4695f74ea5949551df6044720694e204b13d7 2011/12/03 21:00:00 852776 records - OK
cc0embkz 7.0 5580fd78c8614641102fa37faf015524b5e02ea3 2013/07/01 07:41:00 1351 records - OK
ds1fbxkr 7.0 0cb77ee7a3e6545553585eb6df267a86d4fecbe4 2013/04/22 00:14:29 1680 records - OK
n60u01nh 7.0 6cb68b8fab821702ef054f864ff44917414e50fa 2013/02/04 00:13:43 2078 records - OK
n1kn668y 7.0 cfbe9cf43615f7856e4c35f0fc02e2baf12e39e7 2012/12/17 00:14:14 1725 records - OK
alhtvn2b 7.0 047694e79b1a8d295f27ea9c6565062404f84a57 2012/11/12 00:12:52 2050 records - OK
4g0sve0v 7.0 f3413603f4ee1c88018a78c1f6faf2abeb8fa8c1 2012/09/24 00:13:14 1456 records - OK
rvdy5sp4 7.0 8871f579eeb7e5e7b70c6dd898afd27391d7daf4 2012/06/25 00:12:36 1421 records - OK
se2ec0og 7.0 3ee43130fe7fec4b367a791892a444d0a791b29b 2012/03/26 00:12:30 1385 records - OK
y0cquuv0 7.0 fddc5d687537580c7166dbf117d591593bc62261 2012/01/23 01:56:09 1653 records - OK
44t6ofg8 7.0 47656cca26f2beec5fd8105cabfd7f5e8aba8e56 2013/07/01 07:40:52 956 records - OK
8mg524fh 7.0 45cdfad530697916adbfea43a8763a4ab0c95beb 2013/05/20 00:24:48 1426 records - OK
0kof117d 7.0 bd9fd948b79e07c8676018e17a43ee81f5335e36 2013/04/22 00:24:10 1641 records - OK
zguj26jj 7.0 c7f70566b9bae9fd3f5a8d0b56d961f890a55508 2013/03/18 00:23:44 1742 records - OK
k4uekspg 7.0 8893c0d254eb40c78b5c78ea17fbc3be60ea6304 2013/01/21 00:24:33 2016 records - OK
2ni6n45v 7.0 cdf3a9d2dcab57f90c378d9eefacbfd358a42699 2012/12/10 00:23:23 1620 records - OK
ppgxxxg8 7.0 c0726ba000e840272f0810b89051e6daa8799084 2012/11/05 00:23:16 1658 records - OK
bhv54x9n 7.0 216611859de0125bf130d6324d43c9115cb05def 2012/10/08 00:23:20 1465 records - OK
za3wt3r7 7.0 264c14ad60c4423ec292f5f8b182e4448504dfa9 2012/09/10 00:23:14 1588 records - OK
t5tbduu1 7.0 33197bfe9efefa9db33725d240757103c625b601 2012/07/23 00:22:36 1702 records - OK
0o355j0u 7.0 74d8e114edb84b95bc09d5a2a36191d15a61e2cb 2012/06/11 00:22:36 1659 records - OK
xhbw8qg6 7.0 79ca8239f310688d2b9c314fa3d738a34985cce3 2012/04/30 00:22:34 1670 records - OK
5o25y8h5 7.0 aac27e986e3731e5260cb76f5b14558e36660dec 2012/03/12 00:22:28 1729 records - OK
cwb7nkkr 7.0 fa5c96b8be693a20c2a295e3545419e6f117fdc4 2012/01/30 00:23:00 1523 records - OK
9r23485v 7.0 e9b21e0a3578ef2e2067f4876309671ddc78f65f 2011/12/19 00:22:29 1805 records - OK
nphz51gk 7.0 8f7a8f6f55130f6becc5331ab38dc2108746b8aa 2011/12/03 20:00:00 26456 records - OK
s2ts4avm 7.0 e6d52b11d2f7d405ccd31347da3b6fde69825168 2011/12/03 19:00:00 74279 records - OK
3t4zqwg8 7.0 e20ffde4bbc58e0585b0b3b2f324bc91272c2360 2011/12/03 18:00:00 1 record - OK
Total records count: 4174588
Anti-rootkit module version ( ver: 8.3.201306200, api: 5.01/5.01 )
 
Using C:\Users\Johnson\AppData\Local\Temp\75E8A834-955F53D8-1AE65180-2B2DD838\12jlmmz8.key as Dr.Web ® Key file
This Dr.Web ® Key is for 1 computer (A User)
-----------------------------------------------------------------------------
Start scanning
-----------------------------------------------------------------------------
Command line used:-rpcep:\pipe\1E38977A5C -rpcpr:np 
 
Object(s) to scan:
 - Scan processes in memory
 - Scan boot sectors
 - Scan system restore points
 - Scanning for rootkits 
 - C:\
 - D:\
 - E:\
 - F:\
 - G:\
 - H:\
 - C:\asc_rdflag
 - C:\bootmgr
 - C:\BOOTNXT
 - C:\hiberfil.sys
 - C:\pagefile.sys
 - C:\swapfile.sys
 - C:\Windows\system32\
 - C:\Windows\SysWOW64\
 - C:\Users\Johnson\Documents\
 - C:\Windows\TEMP\
 - C:\Users\Johnson\AppData\Local\Temp\
 
c:\windows\system32\drivers\dump_dumpata.sys - file not found
c:\windows\system32\drivers\dump_atapi.sys - file not found
c:\windows\system32\drivers\dump_dumpfve.sys - file not found
c:\windows\syswow64\drivers\x6va012 - file not found
c:\users\johnson\appdata\local\temp\1e293cb35b.sys - file not found
c:\users\johnson\appdata\local\temp\1e2aa44fd5.sys - file not found
System Idle Process - file not found
System Process - file not found
c:\users\johnson\appdata\roaming\microsoft\windows\start menu\programs\startup\34ac3.js - infected with JS.Proslikefan.1
c:\users\johnson\appdata\roaming\microsoft\windows\start menu\programs\startup\34ac3.js - infected
c:\users\johnson\appdata\roaming\77f87\61ee6.js - infected with JS.Proslikefan.1
c:\users\johnson\appdata\roaming\77f87\61ee6.js - infected
Process :0 - read error
Process System:4 - read error
C:\System Volume Information\{01bb4f67-ded5-11e2-be99-902b34f14411}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
C:\System Volume Information\{caddb558-d760-11e2-be97-902b34f14411}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
C:\System Volume Information\{caddc97b-d760-11e2-be97-902b34f14411}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
C:\hiberfil.sys - read error
C:\pagefile.sys - read error
C:\swapfile.sys - read error
C:\Arquivos de Programas - directory
C:\Documents and Settings - directory
C:\LU!G\RagnarokOnline\Ragnarok.exe - probably infected with DLOADER.Trojan
C:\LU!G\RagnarokOnline\Ragnarok.exe - infected
C:\LU!Games\Ragnarok\Ragnarok.exe - probably infected with DLOADER.Trojan
C:\LU!Games\Ragnarok\Ragnarok.exe - infected
C:\NVIDIA\DisplayDriver\310.90\Win8_WinVista_Win7_64\English\Display.Driver\nvidia-smi.1.pd_ - container, read error
C:\NVIDIA\DisplayDriver\314.07\Win8_WinVista_Win7_64\International\Display.Driver\nvidia-smi.1.pd_ - container, read error
C:\Program Files\Arquivos Comuns - directory
C:\Program Files\Common Files\Sistema - directory
C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.0\nvidia-smi.1.pd_ - container, read error
C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.1\nvidia-smi.1.pd_ - container, read error
C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{2056B9AE-A676-435F-A04B-16F2005057A9}\nvidia-smi.1.pd_ - container, read error
C:\Program Files\Windows NT\Acessórios - directory
C:\ProgramData\Application Data - directory
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\59c20b49.qua - container, read error
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\42ace9d9.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\10f3b331.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\42ace9d9.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\10f3b331.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\57c6d0fc.qua - is adware program Adware.Downware.893
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5461cb63.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\57c6d0fc.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\579dd11c.qua - is adware program Adware.Downware.893
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5461cb63.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\579dd11c.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\579dd11c.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4f41e8ac.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\57c6d0fc.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4f41e8ac.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5889dd0c.qua - is adware program Adware.Downware.893
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5a3bc67f.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\57d6c70b.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5a3bc67f.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\57d6c70b.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5889dd0c.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5889dd0c.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\57d4c90e.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\57d4c90e.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5ac1e3d7.qua - is adware program Adware.Downware.893
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5ac1e3d7.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5b8ae9a1.qua - is adware program Adware.Downware.893
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5b8ae9a1.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5d61c910.qua - is adware program Adware.Downware.980
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5d61c910.qua - infected
C:\ProgramData\Avira\AntiVir Desktop\TEMP\avguard1.tmp - read error
C:\ProgramData\Dados de Aplicativos - directory
C:\ProgramData\Desktop - directory
C:\ProgramData\Documentos - directory
C:\ProgramData\Documents - directory
C:\ProgramData\Menu Iniciar - directory
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.log - read error
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbtmp.log - read error
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb - read error
C:\ProgramData\Microsoft\Windows\LocationProvider - directory
C:\ProgramData\Microsoft\Windows\Start Menu\Programas - directory
C:\ProgramData\Microsoft\Windows\SystemData - directory
C:\ProgramData\Modelos - directory
C:\ProgramData\Start Menu - directory
C:\ProgramData\Templates - directory
C:\System Volume Information - directory
C:\Users\All Users\Application Data - directory
C:\Users\All Users\Dados de Aplicativos - directory
C:\Users\All Users\Desktop - directory
C:\Users\All Users\Documentos - directory
C:\Users\All Users\Documents - directory
C:\Users\All Users\Menu Iniciar - directory
C:\Users\All Users\Modelos - directory
C:\Users\All Users\Start Menu - directory
C:\Users\All Users\Templates - directory
C:\Users\Default User - directory
C:\Users\Default\Ambiente de Impressão - directory
C:\Users\Default\Ambiente de Rede - directory
C:\Users\Default\AppData\Local\Application Data - directory
C:\Users\Default\AppData\Local\Dados de Aplicativos - directory
C:\Users\Default\AppData\Local\History - directory
C:\Users\Default\AppData\Local\Histórico - directory
C:\Users\Default\AppData\Local\Temporary Internet Files - directory
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas - directory
C:\Users\Default\Application Data - directory
C:\Users\Default\Configurações Locais - directory
C:\Users\Default\Cookies - directory
C:\Users\Default\Dados de Aplicativos - directory
C:\Users\Default\Documents\Meus Vídeos - directory
C:\Users\Default\Documents\Minhas Imagens - directory
C:\Users\Default\Documents\Minhas Músicas - directory
C:\Users\Default\Documents\My Music - directory
C:\Users\Default\Documents\My Pictures - directory
C:\Users\Default\Documents\My Videos - directory
C:\Users\Default\Local Settings - directory
C:\Users\Default\Menu Iniciar - directory
C:\Users\Default\Meus Documentos - directory
C:\Users\Default\Modelos - directory
C:\Users\Default\My Documents - directory
C:\Users\Default\NetHood - directory
C:\Users\Default\PrintHood - directory
C:\Users\Default\Recent - directory
C:\Users\Default\SendTo - directory
C:\Users\Default\Start Menu - directory
C:\Users\Default\Templates - directory
C:\Users\Johnson\NTUSER.DAT - read error
C:\Users\Johnson\ntuser.dat.LOG1 - read error
C:\Users\Johnson\ntuser.dat.LOG2 - read error
C:\Users\Johnson\Ambiente de Impressão - directory
C:\Users\Johnson\Ambiente de Rede - directory
C:\Users\Johnson\AppData\Local\Dados de Aplicativos - directory
C:\Users\Johnson\AppData\Local\Histórico - directory
C:\Users\Johnson\AppData\Local\Microsoft\Windows\UsrClass.dat - read error
C:\Users\Johnson\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - read error
C:\Users\Johnson\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - read error
C:\Users\Johnson\AppData\Local\Microsoft\Windows\Notifications\WPNPRMRY.tmp - read error
C:\Users\Johnson\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat - read error
C:\Users\Johnson\AppData\Local\Microsoft\Windows\WebCache\V01.log - read error
C:\Users\Johnson\AppData\Local\Temporary Internet Files - directory
C:\Users\Johnson\AppData\Roaming\77f87\61ee6.js - infected with JS.Proslikefan.1
C:\Users\Johnson\AppData\Roaming\Microsoft\Windows\Start Menu\Programas - directory
C:\Users\Johnson\Configurações Locais - directory
C:\Users\Johnson\Cookies - directory
C:\Users\Johnson\Dados de Aplicativos - directory
C:\Users\Johnson\Documents\Meus Vídeos - directory
C:\Users\Johnson\Documents\Minhas Imagens - directory
C:\Users\Johnson\Documents\Minhas Músicas - directory
C:\Users\Johnson\Menu Iniciar - directory
C:\Users\Johnson\Meus Documentos - directory
C:\Users\Johnson\Modelos - directory
C:\Users\Johnson\Recent - directory
C:\Users\Johnson\SendTo - directory
C:\Users\Public\Documents\Meus Vídeos - directory
C:\Users\Public\Documents\Minhas Imagens - directory
C:\Users\Public\Documents\Minhas Músicas - directory
C:\Users\Public\Documents\My Music - directory
C:\Users\Public\Documents\My Pictures - directory
C:\Users\Public\Documents\My Videos - directory
C:\Users\Todos os Usuários\Application Data - directory
C:\Users\Todos os Usuários\Dados de Aplicativos - directory
C:\Users\Todos os Usuários\Desktop - directory
C:\Users\Todos os Usuários\Documentos - directory
C:\Users\Todos os Usuários\Documents - directory
C:\Users\Todos os Usuários\Menu Iniciar - directory
C:\Users\Todos os Usuários\Modelos - directory
C:\Users\Todos os Usuários\Start Menu - directory
C:\Users\Todos os Usuários\Templates - directory
C:\Users\UpdatusUser\ntuser.dat.LOG1 - read error
C:\Users\UpdatusUser\NTUSER.DAT - read error
C:\Users\UpdatusUser\ntuser.dat.LOG2 - read error
C:\Users\UpdatusUser\Ambiente de Impressão - directory
C:\Users\UpdatusUser\Ambiente de Rede - directory
C:\Users\UpdatusUser\AppData\Local\Dados de Aplicativos - directory
C:\Users\UpdatusUser\AppData\Local\Histórico - directory
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - read error
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\UsrClass.dat - read error
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - read error
C:\Users\UpdatusUser\AppData\Local\Temporary Internet Files - directory
C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programas - directory
C:\Users\UpdatusUser\Configurações Locais - directory
C:\Users\UpdatusUser\Cookies - directory
C:\Users\UpdatusUser\Dados de Aplicativos - directory
C:\Users\UpdatusUser\Documents\Meus Vídeos - directory
C:\Users\UpdatusUser\Documents\Minhas Imagens - directory
C:\Users\UpdatusUser\Documents\Minhas Músicas - directory
C:\Users\UpdatusUser\Menu Iniciar - directory
C:\Users\UpdatusUser\Modelos - directory
C:\Users\UpdatusUser\Meus Documentos - directory
C:\Users\UpdatusUser\Recent - directory
C:\Users\UpdatusUser\SendTo - directory
C:\Users\Usuário Padrão - directory
C:\Windows\AppCompat\Programs\Amcache.hve.LOG2 - read error
C:\Windows\AppCompat\Programs\Amcache.hve - read error
C:\Windows\AppCompat\Programs\Amcache.hve.LOG1 - read error
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT - read error
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1 - read error
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2 - read error
C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\4297acdb622a22f27eab8db517dca18b\d227c559ed59c1851db79eec7fa41735\grouping\db.mdb - read error
C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\4297acdb622a22f27eab8db517dca18b\d227c559ed59c1851db79eec7fa41735\grouping\edb.log - read error
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT - read error
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1 - read error
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2 - read error
C:\Windows\System32\LogFiles\WMI\RtBackup - directory
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - read error
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - read error
C:\Windows\System32\catroot2\edb.log - read error
C:\Windows\System32\config\BBI - read error
C:\Windows\System32\config\BBI.LOG1 - read error
C:\Windows\System32\config\BBI.LOG2 - read error
C:\Windows\System32\config\DEFAULT - read error
C:\Windows\System32\config\DEFAULT.LOG1 - read error
C:\Windows\System32\config\DRIVERS - read error
C:\Windows\System32\config\DEFAULT.LOG2 - read error
C:\Windows\System32\config\DRIVERS.LOG1 - read error
C:\Windows\System32\config\DRIVERS.LOG2 - read error
C:\Windows\System32\config\SAM - read error
C:\Windows\System32\config\SAM.LOG1 - read error
C:\Windows\System32\config\SAM.LOG2 - read error
C:\Windows\System32\config\SECURITY - read error
C:\Windows\System32\config\SECURITY.LOG1 - read error
C:\Windows\System32\config\SECURITY.LOG2 - read error
C:\Windows\System32\config\SOFTWARE - read error
C:\Windows\System32\config\SOFTWARE.LOG1 - read error
C:\Windows\System32\config\SOFTWARE.LOG2 - read error
C:\Windows\System32\config\SYSTEM - read error
C:\Windows\System32\config\SYSTEM.LOG1 - read error
C:\Windows\System32\config\SYSTEM.LOG2 - read error
C:\Windows\System32\config\RegBack\DEFAULT - read error
C:\Windows\System32\config\RegBack\SAM - read error
C:\Windows\System32\config\RegBack\SECURITY - read error
C:\Windows\System32\config\RegBack\SOFTWARE - read error
C:\Windows\System32\config\RegBack\SYSTEM - read error
D: - read error
E: - read error
F: - read error
G: - read error
C:\hiberfil.sys - read error
C:\pagefile.sys - read error
C:\swapfile.sys - read error
H: - read error
C:\Windows\system32\LogFiles\WMI\RtBackup - directory
C:\Windows\system32\catroot2\edb.log - read error
C:\Windows\system32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - read error
C:\Windows\system32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - read error
C:\Windows\system32\config\BBI - read error
C:\Windows\system32\config\BBI.LOG1 - read error
C:\Windows\system32\config\BBI.LOG2 - read error
C:\Windows\system32\config\DEFAULT - read error
C:\Windows\system32\config\DEFAULT.LOG1 - read error
C:\Windows\system32\config\DEFAULT.LOG2 - read error
C:\Windows\system32\config\DRIVERS - read error
C:\Windows\system32\config\DRIVERS.LOG1 - read error
C:\Windows\system32\config\DRIVERS.LOG2 - read error
C:\Windows\system32\config\SAM - read error
C:\Windows\system32\config\SAM.LOG1 - read error
C:\Windows\system32\config\SAM.LOG2 - read error
C:\Windows\system32\config\SECURITY - read error
C:\Windows\system32\config\SECURITY.LOG1 - read error
C:\Windows\system32\config\SECURITY.LOG2 - read error
C:\Windows\system32\config\SOFTWARE - read error
C:\Windows\system32\config\SOFTWARE.LOG1 - read error
C:\Windows\system32\config\SOFTWARE.LOG2 - read error
C:\Windows\system32\config\SYSTEM - read error
C:\Windows\system32\config\SYSTEM.LOG1 - read error
C:\Windows\system32\config\SYSTEM.LOG2 - read error
C:\Windows\system32\config\RegBack\DEFAULT - read error
C:\Windows\system32\config\RegBack\SAM - read error
C:\Windows\system32\config\RegBack\SECURITY - read error
C:\Windows\system32\config\RegBack\SOFTWARE - read error
C:\Windows\system32\config\RegBack\SYSTEM - read error
C:\Users\Johnson\Documents\Meus Vídeos - directory
C:\Users\Johnson\Documents\Minhas Imagens - directory
C:\Users\Johnson\Documents\Minhas Músicas - directory
 
Total 141482666149 bytes in 208666 files scanned (374446 objects)
Total 208421 files (374197 objects) are clean
Total 15 files (19 objects) are infected
Total 2 files are suspicious
Total 119 files are raised error condition
Scan time is 00:53:58.765
 
-----------------------------------------------------------------------------
Start curing
-----------------------------------------------------------------------------
c:\users\johnson\appdata\roaming\microsoft\windows\start menu\programs\startup\34ac3.js - fatal error occured
c:\users\johnson\appdata\roaming\77f87\61ee6.js - deleted, reboot required
=============================================================================
Dr.Web Scanner SE for Windows v8.2.0.05230
© Doctor Web, Ltd., 1992-2013
Scan session started 2013/07/01 11:55:48 
Module location : C:\Users\Johnson\AppData\Local\Temp\737984CA-F48E99A6-D5E9B4F4-6AED59E4\
=============================================================================
OPTION [Automatic Apply Actions] NO
OPTION [Turn Off Computer After Scan] NO
OPTION [Use Sound Alerts] NO
OPTION [Block Network] NO
OPTION [Protect Process] NO
OPTION [Protect Raw Disk] NO
Using language: "English"
Available instances: 12
Instances used: 12
Platform: Windows 8 Starter x64/WOW (Build 9200)
API Version: 2.2
Scanning Engine version: 8.1.0.6170
Virus Finding Engine version: 7.0.4.9250
Total 121 virus bases are loaded from C:\Users\Johnson\AppData\Local\Temp\737984CA-F48E99A6-D5E9B4F4-6AED59E4
07pa931w 7.0 bbe7c7b3a3c63ab0d27ae3cfc621a6d49b740e48 2013/07/01 07:40:33 1822 records - OK
gau5b2hq 7.0 215c2d42a54f5188e8159bfd122292450d16f29b 2011/07/25 11:20:03 2 records - OK
az83p58q 7.0 fa04678f170a21ec39077750c8424cfc0f225584 2013/07/01 00:08:41 1 record - OK
laqgny4d 7.0 613a3e4bae38b4e00a7432c24a9cd916fb1c654f 2013/07/01 00:06:34 24654 records - OK
gfivwji6 7.0 b81132c4abffd4d2949531a1219b6bb1c3bad6f7 2013/06/24 00:06:30 14062 records - OK
ua5ygcla 7.0 9aab251475626c658b193cfa2b5f91da471bf8f2 2013/06/17 00:05:57 13350 records - OK
vl6x1jg7 7.0 e1f8aca88745fcdd49dc7ae75e142c41e1faf178 2013/06/10 00:08:13 26371 records - OK
2rg5c02s 7.0 4e8627555a073f6bad5218bad3e69ebc4b93069f 2013/06/03 00:07:47 25525 records - OK
msdlbumv 7.0 f562371c5115143824efde38c9567c34ccbe5d1a 2013/05/27 00:16:19 33200 records - OK
u8a8ygx7 7.0 eccb30ec8ed44456f9b88fe96d9fe0de40e4fa51 2013/05/20 00:11:05 46384 records - OK
ftxh022j 7.0 9b481fbfbe1f564a84f21552da1d30d24e7b01db 2013/05/13 00:07:01 34270 records - OK
xhx25x5h 7.0 1bf754dd720727b5d6803e081c16ff7f4ba7b40b 2013/05/06 00:08:46 41611 records - OK
5fec29vr 7.0 4e883c92513c2d991968fb3e4f27910a63d9a2df 2013/04/29 00:06:36 36105 records - OK
v4gwq06e 7.0 b047d178295ecde53c3cf1c34e4361004569fa33 2013/04/22 00:07:26 31319 records - OK
fknk2ga0 7.0 9207e55a924e4aa989dfde4d8d219cf5cc200ce2 2013/04/15 00:07:56 28216 records - OK
4t8q6jl1 7.0 78855cfb9fbc063889c5405a577fe73188f08789 2013/04/08 00:05:35 23589 records - OK
lkr3hq0s 7.0 cec6d34c79d50608520e81b90a23d91f39df0b27 2013/04/01 00:07:37 26946 records - OK
af9yisir 7.0 fd3c78d78ea4dae4e252a7f7d76db22e1a679be9 2013/03/25 00:05:37 34778 records - OK
bcx8r9ze 7.0 268e71b1123ab5e60fd2f38d269fe5f3d22b3697 2013/03/18 00:06:19 11271 records - OK
m2mbvyvh 7.0 d196879775b0dc0ee8286f2e4def9adedb5b88df 2013/03/11 00:05:36 12046 records - OK
9tfyxh22 7.0 0db61d4e3235481da8493523538ced712db362c2 2013/03/04 00:05:18 21747 records - OK
ojdqayb8 7.0 65f99faf227b51883c9f1c854a3f76806b60affb 2013/02/25 00:06:28 11540 records - OK
dsysogkk 7.0 17bd7383b9c4b214c5c9029171db8ae1455984a0 2013/02/18 00:06:38 15568 records - OK
m8wgshci 7.0 cbe8774953ae403e49370d552b522a5839aa9fdb 2013/02/11 00:06:00 18805 records - OK
zaat1f62 7.0 fb6865c02a3680338e4ee0603579107227313b2b 2013/02/04 00:06:01 32488 records - OK
2ixpn8mc 7.0 95fcd2e24cd9b2ec2610656ffa70b8bf46e86a8b 2013/01/28 00:04:52 15470 records - OK
of94ow0h 7.0 3d710b3dd4580a7eca8c74d2c886d48f5b8b5172 2013/01/21 00:06:27 30093 records - OK
1xiaa9gg 7.0 bddde0b5426b7e5bebd61e1239ca529c87ae6e36 2013/01/14 00:04:41 16158 records - OK
lg84572c 7.0 bc40bd9330301e8d7796f489d03357fb711b3121 2013/01/07 00:04:45 19597 records - OK
9dvofzbx 7.0 805b6089c867549c75f843eac96b759c3f8d101f 2012/12/31 00:05:41 18184 records - OK
oty7up69 7.0 c12a817c1f95bb9fd8238ef0d5f68868a8d95686 2012/12/24 00:05:33 30183 records - OK
8fj474fk 7.0 33def496782eb5b7b1cc93fdb036a1b62fa6a2fd 2012/12/17 00:06:21 25519 records - OK
tqcfcpxt 7.0 422abae03c588822f412aa9aae50578a1d61737e 2012/12/10 00:05:04 20358 records - OK
6qvtl81v 7.0 a4f0d0ecad4fb6e0afdb1925f4e0b7863b9d03fa 2012/12/03 00:06:19 20133 records - OK
5cv2ct20 7.0 86daa918ee3de1e4c1e5dea6f9b5f63544cf8814 2012/11/26 00:05:22 27311 records - OK
ukc4wq20 7.0 6556881c748e1f894eb9c7943ebae67017e1aec2 2012/11/19 00:06:09 29434 records - OK
a4r65qh2 7.0 559141ef34f9e6226bb58560e9b52e4cc5165150 2012/11/12 00:06:22 26900 records - OK
5g3f4awx 7.0 cc55013e63ff89319ec772e34d77056c7108cd3b 2012/11/05 00:05:22 25164 records - OK
pjy4858c 7.0 f477dc247d9b562bb64fd4f46a7dcbdf7124eb60 2012/10/29 00:06:37 30226 records - OK
anj0z54d 7.0 abaf5f7fda7308fcf7573b193bbf2116723e9802 2012/10/22 00:04:37 16441 records - OK
gwui2rez 7.0 5adc85528fb49e201d4bc61eca580d6839cc4a4c 2012/10/15 00:05:04 26289 records - OK
0vprby8u 7.0 da8cf3fbd81206bb3d8103347a439f920a74bbe2 2012/10/08 00:05:51 27278 records - OK
zjvv4nkf 7.0 5988744d3cb357f1a013427d466e2d79ab5f8907 2012/10/01 00:05:11 17444 records - OK
1a6npzry 7.0 d4a0dabf4a4df0f79805c6ccdc025f796765e786 2012/09/24 00:06:30 21205 records - OK
ds9p2oz8 7.0 82ed005784d9e258213070a0cd8bfceff345018d 2012/09/17 00:05:43 11686 records - OK
4zcbqyp1 7.0 a95ae63004b8d857c2db055f4e47c15bfc97f626 2012/09/10 00:04:34 12677 records - OK
7ns3swbz 7.0 c39bf233d25242ae9ed8cf204b9b788c8f45ab79 2012/09/03 00:05:28 10118 records - OK
o6kzqhca 7.0 d37b5484b009947b7cdd3837dafe8148615401c2 2012/08/27 00:05:26 12602 records - OK
ev7qacot 7.0 41bf1347794ab7060dec7aaecc1d1d95cf6fecb5 2012/08/20 00:04:05 18298 records - OK
p8170k1c 7.0 1a997511e5892aaeb69b3db70e06676af36382e3 2012/08/13 00:05:19 17126 records - OK
5wq3ye9m 7.0 f7226c59914e3683e538e668c3b664af3232654d 2012/08/06 00:03:53 20539 records - OK
led1tuz5 7.0 4035c8d3b617bf935a317a8c57efaa8e835a61f4 2012/07/30 00:05:26 19330 records - OK
g199agyn 7.0 09b55bc000f184ed426f1d8b9665669346fe5e71 2012/07/23 00:05:34 19692 records - OK
3koqhzlo 7.0 f746c097f298e94faa9db94e6f64ef9fd4a7b010 2012/07/16 00:05:43 14727 records - OK
g3e9zh4x 7.0 792a6a25a17e764390440cd4c2c6ca5a97ab162f 2012/07/09 00:04:33 19485 records - OK
7weid9p9 7.0 ca9905c39e3d93428a4db65a192debe9fbd7acf7 2012/07/02 00:04:55 22898 records - OK
6nb8jxh3 7.0 dc29c610b866c66ba5327e7830452b2460149a35 2012/06/25 00:05:17 20551 records - OK
vxqfkzdp 7.0 c28739bea153508d12942ac9a61abd475d0a0404 2012/06/18 00:03:35 9661 records - OK
a1u1av4f 7.0 e5b5835a7c512120c5348e31483a4caa2a845d28 2012/06/11 00:04:32 23632 records - OK
rv4chy08 7.0 61853ce89026ef0ebbd80174f1b7dd5d25bbc63a 2012/06/04 00:04:41 12423 records - OK
h7d6jvew 7.0 4e6c9897e153b47ca97b7da48ceed23e555a7761 2012/05/28 00:04:26 15493 records - OK
cw9jnmkx 7.0 35f4c105cecd8ec1fd01714abebf30f8f3efb96e 2012/05/21 00:03:29 13065 records - OK
p32ksc6v 7.0 3522aa84677411aa7d67796bb05ea3ab62f02a71 2012/05/14 00:04:24 16238 records - OK
tvaj5n1s 7.0 7597333540eda537bd42c0a17d4a6526ad247a2e 2012/05/07 00:04:33 11570 records - OK
pg8tpmq0 7.0 867814380363bc6ad605acf4b96e02c54dbd60f7 2012/04/30 00:03:28 15478 records - OK
q7q6x2qe 7.0 3c04f402d91a19039cb9c223c435dc4ea1bb3da4 2012/04/23 00:05:05 11881 records - OK
x1euc1zt 7.0 8d0220a2a50b367e61a51d3b29c2659cde41bb7f 2012/04/16 00:03:29 13578 records - OK
i3yfitb8 7.0 b79dc6f5832ad390108d1880694ec538e8b34bb0 2012/04/09 00:05:02 14292 records - OK
nn69b6li 7.0 8ff7cc095c43c2154275b7a54a89bf365e8daf4a 2012/04/02 00:03:24 14084 records - OK
ht42gtcz 7.0 9502a428b32be4ad08556134e271c9ba03195398 2012/03/26 00:04:43 19126 records - OK
6driea1s 7.0 28c2fabbc645aff41baac12b911a8499ea163536 2012/03/19 00:03:23 14920 records - OK
qzxkjvih 7.0 86de597ff06e58206f94263f2eef33cb41b2530c 2012/03/12 00:03:25 19017 records - OK
xmgylny0 7.0 5bd1d666e7c9ca70c34e591dc6c55314ce4b11af 2012/03/05 00:04:32 19691 records - OK
xjec35ie 7.0 15a9d10c451d2fcf124700f29f557d9bf338e671 2012/02/27 00:03:21 23605 records - OK
p0jd2yp6 7.0 5647d941e5358105ca6558dce78873f06c48d5dc 2012/02/20 00:03:45 19067 records - OK
6u83ljyw 7.0 c9b2600cb665ce34e0ccd0f19e0a88cd44437f51 2012/02/13 00:04:49 19019 records - OK
q21kau98 7.0 9df2e129e78a9d9ab491186da1329c1dd1190e17 2012/02/06 00:05:25 28028 records - OK
wwxa90cq 7.0 b69b9504a51b8777b8e95a4680dc8ac1d8d8c25d 2012/01/30 00:08:41 29444 records - OK
ronji74e 7.0 3d7431bdee1a22d6329e017f348db7760f2645ac 2012/01/23 05:22:13 19353 records - OK
noo3ddnb 7.0 e04570f78fb00d758abdf77c534a460980e102c0 2012/01/16 00:12:31 20747 records - OK
rihip9qa 7.0 2de2479b112c4416e2375343f57ca789b042aecc 2012/01/09 00:04:30 28052 records - OK
xq398x37 7.0 c4bd9612ff1f71d8bd23b4f1bc114eed1ae2ee6b 2012/01/02 00:04:40 12183 records - OK
x2dwz393 7.0 28b1d218ade8f05fdc8550c7456ac3b74f705208 2011/12/26 00:03:33 19984 records - OK
up75s1h1 7.0 539e41e8f3d97a6f347600c7cef903d9f34e0518 2011/12/19 00:08:45 22627 records - OK
jv995deh 7.0 f8e81968965f555bce0d02fc9933fee840b97aaf 2011/12/12 17:20:22 49580 records - OK
y5z5d8p9 7.0 14751e0f442bba3efc08ee12d82a2815c61cfeb6 2011/12/04 05:00:00 45195 records - OK
m4rd62nz 7.0 1a1e6cb9b3096a2cbba2c31d05e11914c0357d52 2011/12/04 04:00:00 165532 records - OK
fq1ts6lo 7.0 0f948a7d416c556bfc8a8be2c2c39f998fee6d9e 2011/12/04 03:00:00 170820 records - OK
udyjdtg5 7.0 9357c3cc73a4a374346a678f197daa22496c7ae5 2011/12/04 02:00:00 171279 records - OK
225azu94 7.0 ae56b06b3d6f1e13c5f10cce4ed68f2cccbf3298 2011/12/04 01:00:00 170253 records - OK
1puna13c 7.0 fdaab5c1079d02c94f20d07c39d638cad79d8771 2011/12/04 00:00:00 170291 records - OK
v8vh89wa 7.0 b59d8841e65d7670b2aae7f2b65734269f6c4fe3 2011/12/03 23:00:00 170501 records - OK
typjp0bg 7.0 3946b1d195434cf7a70d144da71c87559475c58f 2011/12/03 22:00:00 353582 records - OK
rj0d6ke2 7.0 8df4695f74ea5949551df6044720694e204b13d7 2011/12/03 21:00:00 852776 records - OK
cc0embkz 7.0 5580fd78c8614641102fa37faf015524b5e02ea3 2013/07/01 07:41:00 1351 records - OK
ds1fbxkr 7.0 0cb77ee7a3e6545553585eb6df267a86d4fecbe4 2013/04/22 00:14:29 1680 records - OK
n60u01nh 7.0 6cb68b8fab821702ef054f864ff44917414e50fa 2013/02/04 00:13:43 2078 records - OK
n1kn668y 7.0 cfbe9cf43615f7856e4c35f0fc02e2baf12e39e7 2012/12/17 00:14:14 1725 records - OK
alhtvn2b 7.0 047694e79b1a8d295f27ea9c6565062404f84a57 2012/11/12 00:12:52 2050 records - OK
4g0sve0v 7.0 f3413603f4ee1c88018a78c1f6faf2abeb8fa8c1 2012/09/24 00:13:14 1456 records - OK
rvdy5sp4 7.0 8871f579eeb7e5e7b70c6dd898afd27391d7daf4 2012/06/25 00:12:36 1421 records - OK
se2ec0og 7.0 3ee43130fe7fec4b367a791892a444d0a791b29b 2012/03/26 00:12:30 1385 records - OK
y0cquuv0 7.0 fddc5d687537580c7166dbf117d591593bc62261 2012/01/23 01:56:09 1653 records - OK
44t6ofg8 7.0 47656cca26f2beec5fd8105cabfd7f5e8aba8e56 2013/07/01 07:40:52 956 records - OK
8mg524fh 7.0 45cdfad530697916adbfea43a8763a4ab0c95beb 2013/05/20 00:24:48 1426 records - OK
0kof117d 7.0 bd9fd948b79e07c8676018e17a43ee81f5335e36 2013/04/22 00:24:10 1641 records - OK
zguj26jj 7.0 c7f70566b9bae9fd3f5a8d0b56d961f890a55508 2013/03/18 00:23:44 1742 records - OK
k4uekspg 7.0 8893c0d254eb40c78b5c78ea17fbc3be60ea6304 2013/01/21 00:24:33 2016 records - OK
2ni6n45v 7.0 cdf3a9d2dcab57f90c378d9eefacbfd358a42699 2012/12/10 00:23:23 1620 records - OK
ppgxxxg8 7.0 c0726ba000e840272f0810b89051e6daa8799084 2012/11/05 00:23:16 1658 records - OK
bhv54x9n 7.0 216611859de0125bf130d6324d43c9115cb05def 2012/10/08 00:23:20 1465 records - OK
za3wt3r7 7.0 264c14ad60c4423ec292f5f8b182e4448504dfa9 2012/09/10 00:23:14 1588 records - OK
t5tbduu1 7.0 33197bfe9efefa9db33725d240757103c625b601 2012/07/23 00:22:36 1702 records - OK
0o355j0u 7.0 74d8e114edb84b95bc09d5a2a36191d15a61e2cb 2012/06/11 00:22:36 1659 records - OK
xhbw8qg6 7.0 79ca8239f310688d2b9c314fa3d738a34985cce3 2012/04/30 00:22:34 1670 records - OK
5o25y8h5 7.0 aac27e986e3731e5260cb76f5b14558e36660dec 2012/03/12 00:22:28 1729 records - OK
cwb7nkkr 7.0 fa5c96b8be693a20c2a295e3545419e6f117fdc4 2012/01/30 00:23:00 1523 records - OK
9r23485v 7.0 e9b21e0a3578ef2e2067f4876309671ddc78f65f 2011/12/19 00:22:29 1805 records - OK
nphz51gk 7.0 8f7a8f6f55130f6becc5331ab38dc2108746b8aa 2011/12/03 20:00:00 26456 records - OK
s2ts4avm 7.0 e6d52b11d2f7d405ccd31347da3b6fde69825168 2011/12/03 19:00:00 74279 records - OK
3t4zqwg8 7.0 e20ffde4bbc58e0585b0b3b2f324bc91272c2360 2011/12/03 18:00:00 1 record - OK
Total records count: 4174588
Anti-rootkit module version ( ver: 8.3.201306200, api: 5.01/5.01 )
 
Using C:\Users\Johnson\AppData\Local\Temp\737984CA-F48E99A6-D5E9B4F4-6AED59E4\12jlmmz8.key as Dr.Web ® Key file
This Dr.Web ® Key is for 1 computer (A User)
Change language: "Portuguese (Português)"
-----------------------------------------------------------------------------
Start scanning
-----------------------------------------------------------------------------
Command line used:-rpcep:\pipe\1C8999D5 -rpcpr:np 
 
Object(s) to scan:
 - Scan processes in memory
 - Scan boot sectors
 - Scanning for rootkits 
 - C:\asc_rdflag
 - C:\bootmgr
 - C:\BOOTNXT
 - C:\hiberfil.sys
 - C:\pagefile.sys
 - C:\swapfile.sys
 - C:\Windows\system32\
 - C:\Windows\SysWOW64\
 - C:\Users\Johnson\Documents\
 - C:\Windows\TEMP\
 - C:\Users\Johnson\AppData\Local\Temp\
 
c:\windows\system32\drivers\dump_dumpata.sys - file not found
c:\windows\system32\drivers\dump_atapi.sys - file not found
c:\windows\system32\drivers\dump_dumpfve.sys - file not found
c:\users\johnson\appdata\local\temp\1ca10016.sys - file not found
c:\users\johnson\appdata\local\temp\1d5af367.sys - file not found
System Idle Process - file not found
System Process - file not found
Process :0 - read error
Process System:4 - read error
Process audiodg.exe:4456 - read error
C:\swapfile.sys - read error
C:\hiberfil.sys - read error
C:\pagefile.sys - read error
C:\Windows\system32\LogFiles\WMI\RtBackup - directory
C:\Windows\system32\catroot2\edb.log - read error
C:\Windows\system32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - read error
C:\Windows\system32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - read error
C:\Windows\system32\config\BBI - read error
C:\Windows\system32\config\BBI.LOG1 - read error
C:\Windows\system32\config\BBI.LOG2 - read error
C:\Windows\system32\config\DEFAULT - read error
C:\Windows\system32\config\DEFAULT.LOG1 - read error
C:\Windows\system32\config\DEFAULT.LOG2 - read error
C:\Windows\system32\config\DRIVERS - read error
C:\Windows\system32\config\DRIVERS.LOG1 - read error
C:\Windows\system32\config\DRIVERS.LOG2 - read error
C:\Windows\system32\config\SAM - read error
C:\Windows\system32\config\SAM.LOG2 - read error
C:\Windows\system32\config\SAM.LOG1 - read error
C:\Windows\system32\config\SECURITY - read error
C:\Windows\system32\config\SECURITY.LOG1 - read error
C:\Windows\system32\config\SECURITY.LOG2 - read error
C:\Windows\system32\config\SOFTWARE - read error
C:\Windows\system32\config\SOFTWARE.LOG1 - read error
C:\Windows\system32\config\SOFTWARE.LOG2 - read error
C:\Windows\system32\config\SYSTEM - read error
C:\Windows\system32\config\SYSTEM.LOG1 - read error
C:\Windows\system32\config\SYSTEM.LOG2 - read error
C:\Windows\system32\config\RegBack\DEFAULT - read error
C:\Windows\system32\config\RegBack\SAM - read error
C:\Windows\system32\config\RegBack\SECURITY - read error
C:\Windows\system32\config\RegBack\SOFTWARE - read error
C:\Windows\system32\config\RegBack\SYSTEM - read error
C:\Users\Johnson\Documents\Meus Vídeos - directory
C:\Users\Johnson\Documents\Minhas Imagens - directory
C:\Users\Johnson\Documents\Minhas Músicas - directory
 
Total 17914710861 bytes in 23323 files scanned (25760 objects)
Total 23280 files (25714 objects) are clean
There are no infected objects detected
Total 42 files are raised error condition
Scan time is 00:10:13.458
 
 
E este o novo do Hijack This
 
Logfile of HijackThis v1.99.1
Scan saved at 12:18:51, on 01/07/2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
 
Running processes:
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\NewSoft\Presto! PVR (Brazil 1 Seg)\Monitor.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Users\Johnson\Desktop\HijackThis\HijackThis.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://localoem.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://localoem.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft..../?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft..../?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\ADVANC~1\BROWER~1\ASCPlugin_Protection.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ChangeFilterMerit] "C:\Program Files (x86)\NewSoft\Presto! PVR (Brazil 1 Seg)\ChangeFilterMerit.exe"
O4 - HKLM\..\Run: [Presto! PVR (1seg)] "C:\Program Files (x86)\NewSoft\Presto! PVR (Brazil 1 Seg)\Monitor.exe"
O4 - HKLM\..\Run: [OiVelox] C:\Program Files (x86)\Oi\Programmer\OiVeloxCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Johnson\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Advanced SystemCare 6] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [61ee6] C:\Users\Johnson\AppData\Roaming\77f87\61ee6.js
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O11 - Options group: [INTERNATIONAL] International
O13 - Gopher Prefix: 
O16 - DPF: {00001026-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter26 Class) - http://download.netm...26_20130521.cab
O16 - DPF: {0A010259-4F31-42C7-9AE4-35A30D1A7C6D} (NMGridDownCtrl Class) - http://download.netm.../NMGridDown.cab
O16 - DPF: {5C1B293E-DA77-4AFF-8B52-63DEF8C8A071} (NetmarbleAutoUpdater Class) - http://download.netm....1_20091109.cab
O16 - DPF: {89F434A7-4A49-4394-AC02-007480331AE2} (NetmarbleSystemIDInfo Class) - http://download.netm...nfo_1.0.0.1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{564C173A-34A0-4B46-8395-DEDC9077C53E}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Agendamento (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc (file missing)
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - %ProgramFiles%\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %PROGRAMFILES%\Windows Media Player\wmpnetwk.exe (file missing)
 
 
P.S.: Não fiz o do Panda pois não tenho o Cartão de Memória (uma vez que ele não é meu), e também não pretendo usá-lo novamente no meu PC.


#4
JohnsonK

JohnsonK

    Novato

  • Novato
  • Pip
  • 6 posts

Percebi que ficou um arquivo na Quarentena do programa Dr.Web.

Arquivo(s) anexado(s)



#5
CarlosTurco

CarlosTurco

    Assistente

  • Assistente
  • 23.609 posts

Ok,

 

Execute os procedimentos abaixo.

1)

Baixe o AdwCleaner e salve no desktop.
http://general-chang...de/2-adwcleaner

Execute o arquivo adwcleaner.exe

*** Usuários do Windows Vista ou Windows 7 clique com o direito sobre o arquivo adwcleaner.exe, depois clique em execadmin.png.

Clique em Remover.

Abrirá um bloco de notas com o resultado. Selecione, copie e cole o seu conteúdo na próxima resposta.

2)

 

Desative temporariamente seu antivirus, antispywares e firewall, para não causar conflitos.

Faça o download do ComboFix
http://www.bleepingc...nload/combofix/

Salve-o na sua área de trabalho.

  • Feche todas as janelas e programas. Rode o ComboFix.
  • Dê um duplo-clique no combofix.exe e tecle "Sim" para prosseguir.
  • Quando perguntado se deseja instalar o Console de Recuperação, clique em Sim e agüarde.
  • Clique em OK para aceitar o EULA, e depois clique em Sim para continuar a busca por malwares.

Não clique em nada e não aperte nenhuma tecla durante o exame, pois a ferramenta não funcionará corretamente.

Quando a ferramenta terminar de rodar, gerará um log. Poste o conteúdo do arquivo C:\ComboFix.txt na sua próxima resposta.

Importante:

  • É necessário estar conectado durante o procedimento com o ComboFix;
  • É preciso estar logado no sistema com privilégios de administrador.
  • Baixe e SALVE o ComboFix. Na janela de download, onde aparecem as opções Executar / Salvar, clique em Salvar. Não execute o ComboFix na janela do seu navegador.
  • Mantenha seu antivirus, antispywares e firewall desativados durante os procedimentos com o ComboFix. Torne a ativá-los quando terminar tudo.
  • Caso você já tenha usado o Combofix anteriormente, então delete-o e baixe-o novamente.
  • Caso o Console de Recuperação já esteja instalado nesta máquina, o ComboFix não irá lhe sugerir a instalação.
  • Não rode o ComboFix mais do que uma vez. Isso irá sobreescrever o log e atrasará a remoção do(s) malware(s)
  • O ComboFix é uma ferramenta que pode danificar o sistema se for usada incorretamente. Use-o apenas sob supervisão de um analista de malwares.


 



#6
JohnsonK

JohnsonK

    Novato

  • Novato
  • Pip
  • 6 posts

Logs do dois últimos programas

 

Ah, tinha esquecido de avisar. No mesmo dia em que eu coloquei o cartão de memória e daí apareceu a caixinha de erro e tal que não queria fechar "wscript" aí eu usei a ferramenta Advanced SystemCare. Após o PC ser reiniciado estava tudo aparentemente normal, mas até então não usei nenhum outro dispositivo de mídia removível. 

Arquivo(s) anexado(s)


Editado por JohnsonK, 02 julho 2013 - 12:50.


#7
CarlosTurco

CarlosTurco

    Assistente

  • Assistente
  • 23.609 posts

Ok,
 
Desative seu antivirus, antispywares e firewall, para não causar conflitos. Mantenha-os desativados até terminar as instruções.

Selecione e copie o texto dentro do CODE. Abra o Bloco de Notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt.

OBS: Certifique-se de copiar começando pela letra "F".
 

File::
c:\users\Johnson\AppData\Roaming\77f87\61ee6.js

Folder::
c:\users\Johnson\AppData\Roaming\77f87
C:\766

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"61ee6"=-

ClearJavaCache::
 
Reboot::

Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo.


cfscript.gif

O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção.
* Caso isso não aconteça, então reinicie manualmente.

IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando.

Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes.

Aos visitantes: Se estiverem com um problema semelhante, não utilizem esse script, pois o uso sem supervisão pode causar danos ao sistema.


Quando acabar, será gerado um log, que estará em C:\ComboFix.txt.

Poste também um novo log do HijackThis.



#8
JohnsonK

JohnsonK

    Novato

  • Novato
  • Pip
  • 6 posts

Aqui

Arquivo(s) anexado(s)



#9
CarlosTurco

CarlosTurco

    Assistente

  • Assistente
  • 23.609 posts

Ok,

 

Os logs estão limpos. :)
 
Para finalizar:

  • Vá em Iniciar > Executar > digite (ou copie e cole): ComboFix /Uninstall

    2egd02b.png

    Dê o OK. Aguarde, pois isso irá desinstalar o ComboFix.
  • iconjava.png Atualize o Java. Versões antigas têm vunerabilidades que alguns malwares podem usar para infectar seu sistema.
    • Faça download da última versão do Java SE 7u25.
    • Clique em JRE Download
    • Marque a caixa Accept License Agreement..
    • Clique no link para download Windows x86 Offline 30.25 MB jre-7u25-windows-i586.exe e salve no seu desktop.
    • Feche qualquer programa que esteja executando, especialmente navegadores.
    • Vá em Iniciar > Painel de Controle duplo clique em Adicionar ou Remover Programas e remova todas as versões antigas do Java.
      Exemplos de versões antigas
      Java 2 Runtime Environment, SE v1.4.2
      J2SE Runtime Environment 5.0
      J2SE Runtime Environment 5.0 Update 6
    • Selecione qualquer item com nome Java Runtime Environment (JRE ou J2SE).
    • Clique no botão Remover ou Alterar/Remover.
    • Repita quantas vezes for necessária para remover cada versão do Java.
    • Reincie seu computador uma vez que todas as versões do Java tenham sido removidas.
    • Agora vá no seu desktop, clique duas vezes em jre-7u25-windows-i586.exe para instalar a mais nova versão.
    • ATENÇÃO: Desmarque a caixa de instalação da ASK Toolbar.
  • iconadobe.png  Atualize o Adobe Reader. Versões antigas têm vulnerabilidades que são exploradas por malwares.

    Clique aqui e instale a mais nova versão.
  • iconflash.png Mantenha o Flash Player atualizado. Versões antigas também têm vulnerabilidades que são exploradas por malwares. Clique aqui e instale a mais nova versão.
  • worm.pngWorms USB (vírus de pendrive) podem infectar qualquer tipo de dispositivo de armazenamento removível (pendrives, mp3, mp4, celulares, cartões de memória, câmeras fotográficas). Este tipo de malware explora um recurso nativo do Windows chamado Autorun, ou Autoplay (é aquele assistente que aparece quando você insere um cd ou pendrive, perguntando com qual programa você deseja abri-lo). O Autoplay precisa de um arquivo chamado autorun.inf para funcionar.

    Mantenha um cópia limpa e protegida do arquivo autorun.inf em todos os dispositivos removíveis e em todas as unidades do sistema. Deste modo, se acaso você plugar o seu pendrive em algum pc infectado, o malware não vai conseguir sobreescrever o arquivo pré-existente. Mas ainda assim ele poderá copiar seus executáveis maliciosos para o pendrive, tais como .EXE, .SCR, .CMD, .PIF, .BAT, .COM.
    Se você plugar este pendrive em uma máquina limpa e executar algum desses arquivos maliciosos, esse sistema será infectado da mesma forma. Portanto, tenha cuidado e use o bom senso.

    Para criar um arquivo autorun.inf protegido no Windows XP:

    Faça o download do Flash_Disinfector.exe e salve na sua área de trabalho.
    • Conecte todos os dispositivos de armazenamento removível nas portas USBs. Salve o que achar necessário, EXCETO arquivos executáveis, depois formate as mídias, indo em Meu Computador e clicando com o direito sobre a unidade da mídia, escolhendo a opção "Formatar"
    • Execute o Flash_Disinfector.exe.
    • Vá seguindo os prompts que poderão aparecer.
    • Espere até que o programa conclua a busca e depois saia do programa.
    Para Windows Vista e 7: Panda USB Vaccine
  • TFC_icon.pngPara manutenção de sistema, remoção de arquivos temporários e inválidos, baixe TFC, by OldTimer.

    Feche TODOS os programas e execute o TFC. Clique no botão Start e aguarde. Sua área de trabalho irá desaparecer, não se preocupe, isso faz parte do processo.

    Tenha paciência, conforme a quantidade de dados a serem excluídos, o processo pode demorar mais de 2 minutos.

    Quando terminar, você será solicitado a reiniciar seu computador. REINICIE.

    Caso não lhe seja solicitado, reinicie manualmente.
  • iconwu.pngVisite o Windows Update regularmente e verifique por atualizações.
    Novas brechas de segurança são descobertas com freqüência. Muitos malwares exploram essas brechas, infectando sistemas sem depender de nenhuma ação do usuário. A Microsoft corrige essas brechas através das atualizações.
    Por isso é fundamental manter o seu sistema atualizado.
  • Desative e ative novamente a Restauração do Sistema.
  • Aprenda alguns cuidados e dicas para manter seu computador limpo. Leia o artigo Proteja seu pc:
    http://linhadefensiv...proteja-seu-pc/
  • Se não há mais nenhum problema relacionado a malwares, clique no botão denunld.png e peça para fecharem seu tópico.

Se você tiver alguma dúvida relacionada a informática e tecnologia, sinta-se à vontade para postar em qualquer área do forum Linha Defensiva.

Abraço. :legal:



#10
JohnsonK

JohnsonK

    Novato

  • Novato
  • Pip
  • 6 posts

valeu! Brigadão aí!



#11
mikhailovitch

mikhailovitch

    Moderador

  • Moderador
  • 447 posts
PROBLEMA RESOLVIDO
 
Caso queira solicitar a reabertura do tópico, utilize o botão Denunciar para entrar em contato com a moderação.

Nota: Somente o autor pode realizar essa solicitação na área Remoção de Malware.

Não deixe seu tópico inacabado, diga se o seu problema foi resolvido.
http://cartilha.cert.br/