Paulo. 0 Denunciar post Postado Junho 24, 2009 Vem aparecendo aqui sempre que inicia o windows(quando já aparece a área de trabalho) uma janela que diz : Autolt Error Line-1: Error: Variable used without being declared. Mas só aparece ao iniciar mesmo, fora isso não notei nenhuma diferença no desempenho do pc. O log : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:51:51, on 24/6/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Winamp\winampa.exe C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\CyberLink\PowerDVD9\PDVD9Serv.exe C:\Arquivos de programas\Cyberlink\Shared Files\brs.exe C:\Arquivos de programas\QuickTime\qttask.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Documents and Settings\administrator\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\RocketDock\RocketDock.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe G:\opera.exe C:\Documents and Settings\administrator\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file) O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp\winampa.exe" O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [RemoteControl9] "C:\Arquivos de programas\CyberLink\PowerDVD9\PDVD9Serv.exe" O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD9\Language\Language.exe" O4 - HKLM\..\Run: [bDRegion] C:\Arquivos de programas\Cyberlink\Shared Files\brs.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\administrator\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: windows_system_32-dll.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) - O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} - O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O20 - AppInit_DLLs: C:\ARQUIV~1\Google\WEBACC~1\FASTSE~1.DLL O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - (no file) O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - (no file) O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe -- End of file - 9675 bytes Alguém sabe como fazer para essa janela não aparecer mais? Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Junho 24, 2009 :thumbsup: Olá Paulo! :seta: Está constando em seu PC uma versão bem antiga do antivirus Avg. Para remover completamente o Avg de seu computador você pode usar o desinstalador que o Avg oferece: AVG Remover(32bit) - Use esta opção se o seu sistema for de 32 bit. AVG Remover(64bit) - Use esta opção se o seu sistema for de 64 bit. ______________________________________________________________________________ :seta: Depois disto sugiro que você instale um ótimo antivirus gratuito, como o Avira Antivir Personal 9 Free. Para instalar, configurar e usar corretamente o Avira antivir é só seguir as dicas destes tutoriais: Tutorial do Avira Antivir 9 free (instalação e configuração) Tutorial do Avira Antivir 9 free (como usá-lo corretamente) ______________________________________________________________________________ :seta: Depois de instalar e configurar o Avira Antivir seguindo as dicas dos tutoriais acima, atualize-o (faça um update) e reinicie o seu computador e entre pelo Modo de Segurança (apertando a tecla F8 (ou a tecla F5 em alguns computadores) repetidas vezes quando o computador estiver reiniciando e escolhendo a opção Modo Seguro ou Modo de Segurança). Aí quando o computador tiver reiniciado, clique com o botão direito do mouse sobre o símbolo do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Start Antivir > clique na opção Scan system now > e à medida em que forem sendo achados vírus e programas espiões vá enviando eles para a quarentena. Depois de algumas semanas, se o seu computador estiver funcionando normalmente sem estes arquivos que foram para a quarentena, você pode ir na quarentena e excluí-los definitivamente. Quando você tiver removido os virus que o Avira Antivir encontrar, reinicie o computador normalmente. Clique com o botão direito do mouse sobre o ícone do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Start Antivir > clique na opção Reports > dê um duplo clique com o botão esquerdo do mouse sobre o log mais recente e clique no botão Report file > Depois será aberta uma tela com o log, então é só selecionar este Log (Clique no menu: Editar » Selecionar Tudo), depois disso volte novamente no menu: Editar » e clique na opção: Copiar) > Depois disso é só voltar aqui no fórum e postar este log do Avira Antivir juntamente com um novo log do Hijackthis para que eles possam ser analizados. Ficamos no aguardo de sua resposta. Compartilhar este post Link para o post Compartilhar em outros sites
Paulo. 0 Denunciar post Postado Junho 25, 2009 Primeiro, obrigado por responder! Fiz todas as suas dicas e aí estão os logs o log do Avira AntiVir: Avira AntiVir Personal Report file date: quarta-feira, 24 de junho de 2009 19:49 Scanning for 1424788 virus strains and unwanted programs. Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Service Pack 2) [5.1.2600] Boot mode : Save mode Username : Administrador Computer name : PAULO Version information: BUILD.DAT : 9.0.0.403 17961 Bytes 3/6/2009 17:05:00 AVSCAN.EXE : 9.0.3.6 466689 Bytes 11/5/2009 13:14:48 AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/2/2009 14:58:26 LUKE.DLL : 9.0.3.2 209665 Bytes 20/2/2009 15:35:50 LUKERES.DLL : 9.0.2.0 12033 Bytes 27/2/2009 14:58:54 ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 16:30:38 ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 24/6/2009 22:19:16 ANTIVIR2.VDF : 7.1.4.133 2048 Bytes 24/6/2009 22:19:18 ANTIVIR3.VDF : 7.1.4.136 15360 Bytes 24/6/2009 22:19:20 Engineversion : 8.2.0.196 AEVDF.DLL : 8.1.1.1 106868 Bytes 30/4/2009 15:52:06 AESCRIPT.DLL : 8.1.2.10 418171 Bytes 24/6/2009 22:21:36 AESCN.DLL : 8.1.2.3 127347 Bytes 14/5/2009 15:02:02 AERDL.DLL : 8.1.1.3 438645 Bytes 29/10/2008 22:24:42 AEPACK.DLL : 8.1.3.18 401783 Bytes 27/5/2009 20:07:22 AEOFFICE.DLL : 8.1.0.38 196987 Bytes 24/6/2009 22:21:20 AEHEUR.DLL : 8.1.0.134 1802616 Bytes 24/6/2009 22:21:14 AEHELP.DLL : 8.1.3.6 205174 Bytes 24/6/2009 22:19:46 AEGEN.DLL : 8.1.1.46 348533 Bytes 24/6/2009 22:19:40 AEEMU.DLL : 8.1.0.9 393588 Bytes 9/10/2008 18:32:40 AECORE.DLL : 8.1.6.12 180599 Bytes 27/5/2009 20:07:22 AEBB.DLL : 8.1.0.3 53618 Bytes 9/10/2008 18:32:40 AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 12:48:00 AVPREF.DLL : 9.0.0.1 43777 Bytes 5/12/2008 14:32:16 AVREP.DLL : 8.0.0.3 155905 Bytes 20/1/2009 18:34:30 AVREG.DLL : 9.0.0.0 36609 Bytes 5/12/2008 14:32:10 AVARKT.DLL : 9.0.0.3 292609 Bytes 24/3/2009 19:05:42 AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/1/2009 14:37:10 SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/1/2009 19:03:50 SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 12:21:34 NETNT.DLL : 9.0.0.0 11521 Bytes 5/12/2008 14:32:12 RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/5/2009 19:40:00 RCTEXT.DLL : 9.0.37.0 86785 Bytes 17/4/2009 14:19:50 Configuration settings for the scan: Jobname.............................: Complete system scan Configuration file..................: c:\arquivos de programas\avira\antivir desktop\sysscan.avp Logging.............................: low Primary action......................: repair Secondary action....................: quarantine Scan master boot sector.............: on Scan boot sector....................: on Boot sectors........................: C:, G:, Process scan........................: on Scan registry.......................: on Search for rootkits.................: on Integrity checking of system files..: off Scan all files......................: All files Scan archives.......................: on Recursion depth.....................: 20 Smart extensions....................: on Macro heuristic.....................: on File heuristic......................: medium Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+SPR, Start of the scan: quarta-feira, 24 de junho de 2009 19:49 Starting search for hidden objects. The driver could not be initialized. The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'Explorer.EXE' - '1' Module(s) have been scanned Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned Scan process 'unsecapp.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'AAWService.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 14 processes with 14 modules were scanned Starting master boot sector scan: Master boot sector HD0 [iNFO] No virus was found! Master boot sector HD1 [iNFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [iNFO] No virus was found! Boot sector 'G:\' [iNFO] No virus was found! Starting to scan executable files (registry). The registry was scanned ( '48' files ). Starting the file scan: Begin scan in 'C:\' C:\pagefile.sys [WARNING] The file could not be opened! [NOTE] This file is a Windows system file. [NOTE] This file cannot be opened for scanning. C:\System Volume Information\_restore{C2768274-003B-4719-A76C-5E22B1965B5A}\RP761\A0111269.exe [DETECTION] Is the TR/Keygen.BM Trojan [NOTE] The file was moved to '4a73bfe2.qua'! Begin scan in 'G:\' <HD_320GB> G:\aopsfjafjoslsfl\Jogos\gameboy(color e advance)\gameboy(color e advance),\TGB_Dual_7.zip [0] Archive type: ZIP --> devices/tbr_dll.dll [DETECTION] Is the TR/Gologger.D.3 Trojan [NOTE] The file was moved to '4a84c39b.qua'! G:\aopsfjafjoslsfl\programas\Nero 9.4.13.2 Ultra Edition 2009 + Working Keygen [h33t].rar [0] Archive type: RAR --> Keygen.exe [DETECTION] Contains a recognition pattern of the (harmful) BDS/Bifrose.bbld.20 back-door program [NOTE] The file was moved to '4ab4c58f.qua'! End of the scan: quarta-feira, 24 de junho de 2009 21:36 Used time: 1:46:18 Hour(s) The scan has been done completely. 12421 Scanned directories 411098 Files were scanned 3 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 3 Files were moved to quarantine 0 Files were renamed 1 Files cannot be scanned 411094 Files not concerned 8261 Archives were scanned 1 Warnings 4 Notes e o novo log do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:01:45, on 24/6/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Winamp\winampa.exe C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\CyberLink\PowerDVD9\PDVD9Serv.exe C:\Arquivos de programas\Cyberlink\Shared Files\brs.exe C:\Arquivos de programas\QuickTime\qttask.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Documents and Settings\administrator\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\RocketDock\RocketDock.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe C:\WINDOWS\system32\notepad.exe G:\opera.exe C:\Documents and Settings\administrator\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\ARQUIV~1\SPEEDB~1\vaproxy.pac O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file) O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp\winampa.exe" O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [RemoteControl9] "C:\Arquivos de programas\CyberLink\PowerDVD9\PDVD9Serv.exe" O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD9\Language\Language.exe" O4 - HKLM\..\Run: [bDRegion] C:\Arquivos de programas\Cyberlink\Shared Files\brs.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\administrator\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: windows_system_32-dll.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) - O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} - O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O20 - AppInit_DLLs: C:\ARQUIV~1\Google\WEBACC~1\FASTSE~1.DLL O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - (no file) O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - (no file) O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe -- End of file - 10367 bytes Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Junho 26, 2009 :thumbsup: Três problemas foram removidos pelo Avira. :seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked: O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file) ________________________________________________________________________________ :seta: Há programas desnecessários iniciando junto com o Windows, o que torna o seu PC mais lento. Para corrigir isto, siga as dicas deste tutorial: Escolhendo Programas que Iniciam com o PC De preferência deixe apenas os programas de segurança (anti-vírus/anti-spywares/firewall) iniciarem junto com o Windows. Use também o programa Ccleaner, indicado neste tutorial acima, para fazer uma limpeza e otimização do PC agora e de tempos em tempos. Para fazer esta limpeza com o Ccleaner faça o seguinte: Abra o Ccleaner > clique em Executar Limpeza > Clique em Ok. Após isto, clique em Registro > Procurar erros > Corrigir erros selecionados ________________________________________________________________________________ :seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: Baixe o ComboFix em: ComboFix 1) Desabilite o seu anti-vírus temporariamente; 2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos); 3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Clique em “SIM” para continuar. 4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console antes de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura. Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente. Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA. Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADO COM SUCESSO”. Clique sobre “SIM” para continuar a varredura. 5) O ComboFix iniciará o AUTOSCAN (aguarde). ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco). Ao término do processo a máquina será reiniciada para a emissão do relatório. 6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log dele estará em C:\ComboFix.txt. 7) Reabilite o seu anti-vírus; OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Em último caso, se não for possível executar o Combofix no Modo Normal do Windows, tente utilizar o ComboFix em MODO SEGURO (reiniciando o computador e pressionando a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização e escolha a opção Modo Seguro na tela que se apresenta) e repita o procedimento; OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB. * Se por algum motivo você precisar parar ou sair do ComboFix, tecle "N". * Se perder a conexão com a internet, reinicie o computador. Caso o problema persista, abra Conexões de Rede no Painel de Controle, clique com o botão direito do mouse sobre a sua conexão com a internet e em "Reparar"; Poste o log do Combofix que estará em C:\ComboFix.txt juntamente com um novo log do Hijackthis em sua próxima resposta e nos diga como está o seu PC depois disto. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
Paulo. 0 Denunciar post Postado Junho 26, 2009 Antonio, fiz todas as suas instruções, mas infelizmente aquela janelinha continua aparecendo (http://img195.imageshack.us/img195/3366/imagemxaz.jpg) ao iniciar o computador(só aparece mesmo nessa ocasião) :unsure: Acho até que nem é um problema de malware! E eu não consigo desistalar esse AVG, mesmo usando o AVG Remover ! e na aba Ferramentas do CCleaner > Desinstalar programas ele também não aparece! Então para usar o Combofix só consegui desativar mesmo o Avira AntiVir ! Mas mesmo assim consegui usar o ComboFix e aqui estão os logs: log do ComboFix: ComboFix 09-06-26.02 - administrator 26/06/2009 16:55.1 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.447.27 [GMT -3:00] Executando de: c:\documents and settings\administrator\Desktop\ComboFix.exe AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} AV: AVG 7.5.441 *On-access scanning enabled* (Updated) {41564737-3200-1071-989B-0000E87B4FB1} . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\new.exe c:\windows\patch.exe c:\windows\system32\Process.exe c:\windows\system32\SrchSTS.exe c:\windows\system32\tmp.reg . (((((((((((((((( Arquivos/Ficheiros criados de 2009-05-26 to 2009-06-26 )))))))))))))))))))))))))))) . 2009-06-26 16:22 . 2009-06-26 16:22 -------- d-----w- c:\arquivos de programas\Perfect Optimizer 2009-06-26 04:04 . 2009-06-26 04:04 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\AVS4YOU 2009-06-26 03:54 . 2009-06-26 03:54 -------- d-----w- c:\arquivos de programas\Arquivos comuns\AVSMedia 2009-06-26 03:54 . 2007-09-27 17:22 261632 ----a-w- c:\windows\system32\mcdvd_32.dll 2009-06-26 03:54 . 2003-05-22 02:50 1700352 ----a-w- c:\windows\system32\GdiPlus.dll 2009-06-26 03:54 . 2002-01-05 18:48 974848 ----a-w- c:\windows\system32\mfc70.dll 2009-06-26 03:54 . 2009-06-26 03:54 -------- d-----w- c:\arquivos de programas\AVS4YOU 2009-06-26 02:08 . 2009-06-26 02:08 -------- d-----w- C:\rsit 2009-06-25 21:12 . 2009-06-25 21:12 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\NeroDigital 2009-06-24 23:47 . 2009-06-24 23:47 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Winamp 2009-06-24 22:48 . 2009-06-24 22:48 -------- d-sh--w- c:\documents and settings\Administrador\IETldCache 2009-06-24 21:51 . 2009-03-30 13:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys 2009-06-24 21:51 . 2009-02-13 15:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys 2009-06-24 21:51 . 2009-02-13 15:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys 2009-06-24 21:51 . 2009-06-24 21:51 -------- d-----w- c:\arquivos de programas\Avira 2009-06-24 06:04 . 2009-06-24 06:04 -------- d-----w- c:\arquivos de programas\MSXML 4.0 2009-06-24 02:30 . 2009-03-24 19:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-06-24 02:26 . 2009-06-24 02:26 -------- d-----r- c:\documents and settings\LocalService\Meus documentos 2009-06-24 02:00 . 2009-06-24 01:58 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-06-24 01:59 . 2009-06-24 01:59 314200 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Lavasoft\Ad-Aware\update\threatwork.exe 2009-06-24 01:57 . 2009-06-24 01:57 518488 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Lavasoft\Ad-Aware\update\AAWTray.exe 2009-06-24 01:57 . 2009-06-24 01:57 1003344 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Lavasoft\Ad-Aware\update\AAWService.exe 2009-06-24 01:48 . 2009-01-18 21:43 2892112 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe 2009-06-24 01:48 . 2009-06-24 01:48 -------- d--h--w- c:\documents and settings\All Users\Dados de aplicativos\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-06-24 01:28 . 2009-06-24 01:28 -------- d-----w- c:\arquivos de programas\VS Revo Group 2009-06-24 01:27 . 2009-06-24 01:27 -------- d-----w- c:\arquivos de programas\RenomearTudo 2009-06-23 19:36 . 2009-06-23 19:36 -------- d-----w- c:\arquivos de programas\FormatFactory 2009-06-23 18:06 . 2009-06-23 18:07 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\InterVideo 2009-06-23 17:52 . 2009-06-23 17:52 -------- d-----w- c:\arquivos de programas\QuickTime 2009-06-23 17:51 . 2009-06-23 17:51 -------- d-----w- c:\arquivos de programas\Apple Software Update 2009-06-23 17:47 . 2009-06-23 17:47 -------- d-----w- c:\arquivos de programas\InterVideo Information Service 2009-06-23 17:47 . 2009-06-23 17:47 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Ulead 2009-06-23 17:45 . 2009-06-23 17:45 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\InstallShield 2009-06-23 06:07 . 2009-06-23 06:07 -------- d-----w- c:\arquivos de programas\RocketDock 2009-06-23 02:52 . 2009-06-23 02:52 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\Nero 2009-06-23 02:25 . 2009-06-23 02:25 -------- d-----w- c:\arquivos de programas\Windows Sidebar 2009-06-23 01:50 . 2009-06-23 01:50 -------- d-----w- c:\arquivos de programas\Nero 2009-06-23 01:49 . 2009-06-23 01:49 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Nero 2009-06-23 01:49 . 2009-06-23 01:49 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Nero 2009-06-23 00:56 . 2009-06-23 00:56 -------- d-----w- c:\arquivos de programas\uTorrent Ultra Accelerator 2009-06-22 21:38 . 2009-06-22 21:38 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\CyberLink 2009-06-22 21:34 . 2009-06-22 21:34 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\CyberLink 2009-06-22 21:29 . 2003-05-21 15:50 24576 ----a-w- c:\windows\system32\msxml3a.dll 2009-06-22 21:28 . 2009-06-22 21:28 -------- d-----w- c:\arquivos de programas\Arquivos comuns\CyberLink 2009-06-22 20:42 . 2009-06-25 18:31 53319 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Temp\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe 2009-06-22 20:42 . 2009-06-22 20:42 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Temp 2009-06-22 17:01 . 2009-06-22 17:01 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\COWON 2009-06-22 16:59 . 2009-06-22 16:59 -------- d-----w- c:\arquivos de programas\Arquivos comuns\COWON 2009-06-22 16:59 . 2009-06-22 16:59 -------- d-----w- c:\arquivos de programas\JetAudio 2009-06-22 16:58 . 2009-06-22 16:58 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\InstallShield 2009-06-22 15:52 . 2009-06-22 15:52 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\dvdcss 2009-06-22 15:51 . 2009-06-22 15:51 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\vlc 2009-06-22 15:50 . 2009-06-22 15:50 -------- d-----w- c:\arquivos de programas\VideoLAN 2009-06-20 00:23 . 2009-06-20 00:23 -------- d-----w- c:\arquivos de programas\Lavalys 2009-06-11 19:24 . 2009-04-30 21:14 12800 ------w- c:\windows\system32\dllcache\xpshims.dll 2009-06-11 19:24 . 2009-04-30 21:14 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-10 00:12 . 2009-06-10 00:12 -------- d-----w- c:\arquivos de programas\Palavras-Cruzadas 8.0 . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-25 18:19 . 2006-01-07 00:05 2728 ----a-w- c:\windows\system32\d3d9caps.dat 2009-06-24 01:59 . 2009-06-24 01:58 25440 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Lavasoft\Ad-Aware\update\savapibridge.dll 2009-06-22 12:54 . 2001-10-28 18:07 61400 ----a-w- c:\windows\system32\perfc016.dat 2009-06-22 12:54 . 2001-10-28 18:07 413126 ----a-w- c:\windows\system32\perfh016.dat 2009-05-15 11:02 . 2009-05-15 11:02 2373416 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Nero\Nero\DrWeb\DrWeb32.dll 2009-05-15 10:50 . 2009-05-15 10:50 2373416 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Nero\Nero 9\DrWeb\DrWeb32.dll 2009-05-13 05:03 . 2004-08-04 06:45 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-08 19:46 . 2009-05-08 19:46 -------- d-----w- c:\arquivos de programas\Arquivos comuns\xing shared 2009-05-08 19:45 . 2003-03-18 23:14 499712 ----a-w- c:\windows\system32\msvcp71.dll 2009-05-08 19:24 . 2009-05-08 19:24 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\Winamp 2009-05-07 15:43 . 2004-08-04 06:45 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-19 20:10 . 2004-08-04 06:38 1846784 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 15:17 . 2004-08-04 06:45 584192 ----a-w- c:\windows\system32\rpcrt4.dll 2004-07-22 13:51 . 2004-07-22 13:51 3432656 ----a-w- c:\arquivos de programas\ManagedDX.CAB 2004-07-20 01:58 . 2004-07-20 01:58 1156363 ----a-w- c:\arquivos de programas\BDANT.cab 2004-07-20 01:53 . 2004-07-20 01:53 976020 ----a-w- c:\arquivos de programas\BDAXP.cab 2004-07-09 17:17 . 2004-07-09 17:17 13265040 ----a-w- c:\arquivos de programas\dxnt.cab 2004-07-09 12:13 . 2004-07-09 12:13 15493481 ----a-w- c:\arquivos de programas\DirectX.cab 2004-07-09 12:13 . 2004-07-09 12:13 703080 ----a-w- c:\arquivos de programas\BDA.cab 2004-07-09 07:08 . 2004-07-09 07:08 472576 ----a-w- c:\arquivos de programas\dxsetup.exe 2004-07-09 07:08 . 2004-07-09 07:08 2242560 ----a-w- c:\arquivos de programas\dsetup32.dll 2004-07-09 06:03 . 2004-07-09 06:03 62976 ----a-w- c:\arquivos de programas\DSETUP.dll 2009-04-18 22:42 . 2008-01-19 01:55 67688 ----a-w- c:\arquivos de programas\mozilla firefox\components\jar50.dll 2009-04-18 22:42 . 2008-01-19 01:55 54368 ----a-w- c:\arquivos de programas\mozilla firefox\components\jsd3250.dll 2009-04-18 22:42 . 2008-01-19 01:55 34944 ----a-w- c:\arquivos de programas\mozilla firefox\components\myspell.dll 2009-04-18 22:42 . 2008-01-19 01:55 46712 ----a-w- c:\arquivos de programas\mozilla firefox\components\spellchk.dll 2009-04-18 22:42 . 2008-01-19 01:55 172136 ----a-w- c:\arquivos de programas\mozilla firefox\components\xpinstal.dll 2004-12-06 01:55 . 2004-12-06 01:55 56 --sh--r- c:\windows\system32\4525EC329C.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088] "RocketDock"="c:\arquivos de programas\RocketDock\RocketDock.exe" [2007-09-02 495616] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpeedBitVideoAccelerator"="c:\arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe" [2008-06-07 2705008] "Ad-Watch"="c:\arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-24 518488] "avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] "DWQueuedReporting"="c:\arquiv~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 36040] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ windows_system_32-dll.exe [2009-6-11 337495] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0lsdelete [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^administrator^Menu Iniciar^Programas^Inicializar^BHODemon 2.0.lnk] backup=c:\windows\pss\BHODemon 2.0.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk] backup=c:\windows\pss\Microsoft Office.lnkCommon Startup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Atualizador - Puxa Rápido HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeskAd Service HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostStartTrayApp HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TM Outbreak Agent HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\K-Lite\\eMule\\emule.exe"= "c:\\Arquivos de programas\\uTorrent\\utorrent.exe"= "c:\\Arquivos de programas\\Mozilla Firefox\\FIREFOX.EXE"= "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Opera\\Opera.exe"= "c:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe"= "c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"= "g:\\opera.exe"= "c:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAccelerator.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "4662:TCP"= 4662:TCP:porta legal "4672:UDP"= 4672:UDP:porta legal 2 R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [23/6/2009 23:00 64160] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [24/6/2009 18:51 108289] R2 sbbotdi;sbbotdi;c:\arquiv~1\SPEEDB~1\sbbotdi.sys [10/3/2007 11:02 35584] R2 VideoAcceleratorService;VideoAcceleratorService;c:\arquiv~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm --> c:\arquiv~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?] S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [21/9/2006 12:24 450400] S3 FXDRV;FXDRV;\??\d:\fxdrv.sys --> d:\Fxdrv.sys [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Conteúdo da pasta 'Tarefas Agendadas' 2009-06-26 c:\windows\Tasks\User_Feed_Synchronization-{E85D7ADC-D05F-4F20-B134-EDF5136335A4}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 07:31] 2009-06-23 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2006-08-29 17:21] 2009-06-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\arquivos de programas\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 01:58] . - - - - ORFÃOS REMOVIDOS - - - - Notify-WgaLogon - (no file) SafeBoot-Lavasoft Ad-Aware Service MSConfigStartUp-pccguide - (no file) MSConfigStartUp-PCClient - (no file) . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Backward &Links IE: Cac&hed Snapshot of Page IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~1\Office10\EXCEL.EXE/3000 IE: shorten url - http://www.cjb.net/menuext.html IE: Si&milar Pages TCP: {01EBD1BD-D540-44FD-9A92-A33BB92BDC7F} = 208.67.220.220,208.67.222.222 TCP: {0416794C-9083-4544-8163-0CFA90D1BAAB} = 208.67.220.220,208.67.222.222 TCP: {04F3740A-F11D-4900-B82A-564CCB9D4053} = 208.67.220.220,208.67.222.222 TCP: {3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE} = 208.67.220.220,208.67.222.222 TCP: {7862CE84-3DED-42EE-9750-CDA60936645C} = 208.67.220.220,208.67.222.222 TCP: {A0CB817D-AD60-4906-ACEC-72A8597BEA66} = 208.67.220.220,208.67.222.222 TCP: {BA9F9753-48FF-4E38-A888-5DA40DBCFEA4} = 208.67.220.220,208.67.222.222 TCP: {BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F} = 208.67.220.220,208.67.222.222 TCP: {DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0} = 208.67.220.220,208.67.222.222 TCP: {E51DCA47-FE65-4BF2-9868-5777F46E8306} = 208.67.220.220,208.67.222.222 DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} FF - ProfilePath - c:\documents and settings\administrator\Dados de aplicativos\Mozilla\Firefox\Profiles\g1igenwf.Novo perfil criado dia 09.07.2008\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q= FF - prefs.js: browser.search.selectedEngine - BS_Player Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1750559&SearchSource=13 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&q= FF - component: c:\arquivos de programas\Google\Web Accelerator\firefox\components\GoogleWebAccFirefox.dll FF - component: c:\arquivos de programas\Mozilla Firefox\components\xpinstal.dll FF - component: c:\documents and settings\administrator\Dados de aplicativos\Mozilla\Firefox\Profiles\g1igenwf.Novo perfil criado dia 09.07.2008\extensions\{31513E58-F253-47ad-86DB-D5F21E905429}\components\mintray-9178506d-2005072516-trunk.dll FF - component: c:\documents and settings\administrator\Dados de aplicativos\Mozilla\Firefox\Profiles\g1igenwf.Novo perfil criado dia 09.07.2008\extensions\piclens@cooliris.com\components\piclensstub.dll FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-26 17:04 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_USERS\S-1-5-21-602162358-1060284298-1202660629-1003\Software\G*e*n*i*e*"!\FM Genie Scout] "LoadLangDB"=dword:00000001 "CompressHistoryPoints"=dword:00000000 "HighlightedAttributes"=dword:00000000 "HighQualityGUI"=dword:00000000 "ShowHistory"=dword:00000001 "WindowState"=dword:00000002 "Currency"=dword:00000056 "WindowHeight"=dword:00000250 "WindowWidth"=dword:0000032c "WindowLeft"=dword:0000006a "WindowTop"=dword:00000058 "AdvancedGeneration"=dword:00000001 [HKEY_USERS\S-1-5-21-602162358-1060284298-1202660629-1003\Software\G*e*n*i*e*"!\FM Genie Scout\Columns\Players] "Position0"=dword:00000000 "Visible0"=dword:00000001 "Width0"=dword:0000007d "Position1"=dword:00000001 "Visible1"=dword:00000001 "Width1"=dword:00000064 "Position2"=dword:00000002 "Visible2"=dword:00000001 "Width2"=dword:00000064 "Position3"=dword:00000003 "Visible3"=dword:00000001 "Width3"=dword:00000037 "Position4"=dword:00000005 "Visible4"=dword:00000001 "Width4"=dword:00000028 "Position5"=dword:00000006 "Visible5"=dword:00000001 "Width5"=dword:00000028 "Position6"=dword:00000004 "Visible6"=dword:00000001 "Width6"=dword:00000028 "Position7"=dword:00000008 "Visible7"=dword:00000001 "Width7"=dword:0000004b "Position8"=dword:00000009 "Visible8"=dword:00000001 "Width8"=dword:0000004b "Position9"=dword:0000000a "Visible9"=dword:00000001 "Width9"=dword:00000050 "Position10"=dword:0000000c "Visible10"=dword:00000000 "Width10"=dword:00000050 "Position11"=dword:0000000d "Visible11"=dword:00000001 "Width11"=dword:0000004b "Position12"=dword:0000000e "Visible12"=dword:00000000 "Width12"=dword:0000002d "Position13"=dword:0000000f "Visible13"=dword:00000000 "Width13"=dword:0000003c "Position14"=dword:00000010 "Visible14"=dword:00000000 "Width14"=dword:0000004b "Position15"=dword:00000011 "Visible15"=dword:00000000 "Width15"=dword:00000064 "Position16"=dword:00000012 "Visible16"=dword:00000000 "Width16"=dword:00000064 "Position17"=dword:00000013 "Visible17"=dword:00000000 "Width17"=dword:0000004b "Position18"=dword:00000014 "Visible18"=dword:00000000 "Width18"=dword:00000064 "Position19"=dword:00000015 "Visible19"=dword:00000000 "Width19"=dword:0000003c "Position20"=dword:00000016 "Visible20"=dword:00000000 "Width20"=dword:0000004b "Position21"=dword:00000017 "Visible21"=dword:00000000 "Width21"=dword:00000050 "Position22"=dword:00000018 "Visible22"=dword:00000000 "Width22"=dword:00000073 "Position23"=dword:00000019 "Visible23"=dword:00000000 "Width23"=dword:00000050 "Position24"=dword:0000001a "Visible24"=dword:00000000 "Width24"=dword:0000005a "Position25"=dword:0000001b "Visible25"=dword:00000000 "Width25"=dword:0000006e "Position26"=dword:0000001c "Visible26"=dword:00000000 "Width26"=dword:00000064 "Position27"=dword:0000001d "Visible27"=dword:00000000 "Width27"=dword:00000087 "Position28"=dword:0000001e "Visible28"=dword:00000000 "Width28"=dword:00000064 "Position29"=dword:0000001f "Visible29"=dword:00000000 "Width29"=dword:00000064 "Position30"=dword:00000020 "Visible30"=dword:00000000 "Width30"=dword:00000046 "Position31"=dword:00000021 "Visible31"=dword:00000000 "Width31"=dword:0000004b "Position32"=dword:00000022 "Visible32"=dword:00000000 "Width32"=dword:00000046 "Position33"=dword:00000023 "Visible33"=dword:00000000 "Width33"=dword:0000004b "Position34"=dword:00000024 "Visible34"=dword:00000000 "Width34"=dword:0000003c "Position35"=dword:00000026 "Visible35"=dword:00000000 "Width35"=dword:00000064 "Position36"=dword:0000002a "Visible36"=dword:00000000 "Width36"=dword:00000073 "Position37"=dword:0000002c "Visible37"=dword:00000000 "Width37"=dword:0000005f "Position38"=dword:0000002f "Visible38"=dword:00000000 "Width38"=dword:00000091 "Position39"=dword:00000031 "Visible39"=dword:00000000 "Width39"=dword:0000003c "Position40"=dword:00000028 "Visible40"=dword:00000000 "Width40"=dword:0000005a "Position41"=dword:00000032 "Visible41"=dword:00000000 "Width41"=dword:00000041 "Position42"=dword:00000025 "Visible42"=dword:00000000 "Width42"=dword:00000050 "Position43"=dword:00000027 "Visible43"=dword:00000000 "Width43"=dword:00000055 "Position44"=dword:00000029 "Visible44"=dword:00000000 "Width44"=dword:0000005f "Position45"=dword:00000033 "Visible45"=dword:00000000 "Width45"=dword:00000050 "Position46"=dword:00000034 "Visible46"=dword:00000000 "Width46"=dword:0000004b "Position47"=dword:00000035 "Visible47"=dword:00000000 "Width47"=dword:0000004b "Position48"=dword:00000036 "Visible48"=dword:00000000 "Width48"=dword:00000046 "Position49"=dword:00000037 "Visible49"=dword:00000000 "Width49"=dword:00000032 "Position50"=dword:00000038 "Visible50"=dword:00000000 "Width50"=dword:0000003c "Position51"=dword:00000039 "Visible51"=dword:00000000 "Width51"=dword:0000004b "Position52"=dword:0000003a "Visible52"=dword:00000000 "Width52"=dword:0000003c "Position53"=dword:0000003b "Visible53"=dword:00000000 "Width53"=dword:00000037 "Position54"=dword:0000003c "Visible54"=dword:00000000 "Width54"=dword:00000069 "Position55"=dword:0000003d "Visible55"=dword:00000000 "Width55"=dword:0000005a "Position56"=dword:00000040 "Visible56"=dword:00000000 "Width56"=dword:0000004b "Position57"=dword:00000041 "Visible57"=dword:00000000 "Width57"=dword:0000004b "Position58"=dword:00000042 "Visible58"=dword:00000000 "Width58"=dword:00000037 "Position59"=dword:00000043 "Visible59"=dword:00000000 "Width59"=dword:0000003c "Position60"=dword:00000044 "Visible60"=dword:00000000 "Width60"=dword:0000003c "Position61"=dword:00000045 "Visible61"=dword:00000000 "Width61"=dword:00000041 "Position62"=dword:00000046 "Visible62"=dword:00000000 "Width62"=dword:00000055 "Position63"=dword:00000047 "Visible63"=dword:00000000 "Width63"=dword:0000003c "Position64"=dword:00000048 "Visible64"=dword:00000000 "Width64"=dword:0000003c "Position65"=dword:00000049 "Visible65"=dword:00000000 "Width65"=dword:0000004b "Position66"=dword:0000004a "Visible66"=dword:00000000 "Width66"=dword:0000003c "Position67"=dword:0000004b "Visible67"=dword:00000000 "Width67"=dword:00000046 "Position68"=dword:0000004c "Visible68"=dword:00000000 "Width68"=dword:00000028 "Position69"=dword:0000004d "Visible69"=dword:00000000 "Width69"=dword:00000041 "Position70"=dword:0000004e "Visible70"=dword:00000000 "Width70"=dword:0000003c "Position71"=dword:0000004f "Visible71"=dword:00000000 "Width71"=dword:00000069 "Position72"=dword:00000050 "Visible72"=dword:00000000 "Width72"=dword:00000041 "Position73"=dword:00000051 "Visible73"=dword:00000000 "Width73"=dword:0000005f "Position74"=dword:00000052 "Visible74"=dword:00000000 "Width74"=dword:0000003c "Position75"=dword:00000053 "Visible75"=dword:00000000 "Width75"=dword:00000037 "Position76"=dword:00000054 "Visible76"=dword:00000000 "Width76"=dword:0000004b "Position77"=dword:00000055 "Visible77"=dword:00000000 "Width77"=dword:00000050 "Position78"=dword:00000056 "Visible78"=dword:00000000 "Width78"=dword:00000037 "Position79"=dword:00000057 "Visible79"=dword:00000000 "Width79"=dword:00000037 "Position80"=dword:00000058 "Visible80"=dword:00000000 "Width80"=dword:0000005a "Position81"=dword:00000059 "Visible81"=dword:00000000 "Width81"=dword:0000004b "Position82"=dword:0000005a "Visible82"=dword:00000000 "Width82"=dword:00000055 "Position83"=dword:0000005b "Visible83"=dword:00000000 "Width83"=dword:0000002d "Position84"=dword:0000005c "Visible84"=dword:00000000 "Width84"=dword:00000037 "Position85"=dword:0000005d "Visible85"=dword:00000000 "Width85"=dword:0000003c "Position86"=dword:0000005e "Visible86"=dword:00000000 "Width86"=dword:00000046 "Position87"=dword:0000005f "Visible87"=dword:00000000 "Width87"=dword:0000003c "Position88"=dword:00000060 "Visible88"=dword:00000000 "Width88"=dword:0000005a "Position89"=dword:00000061 "Visible89"=dword:00000000 "Width89"=dword:0000003c "Position90"=dword:00000062 "Visible90"=dword:00000000 "Width90"=dword:00000050 "Position91"=dword:00000063 "Visible91"=dword:00000000 "Width91"=dword:00000046 "Position92"=dword:00000064 "Visible92"=dword:00000000 "Width92"=dword:0000005a "Position93"=dword:00000065 "Visible93"=dword:00000000 "Width93"=dword:00000037 "Position94"=dword:00000066 "Visible94"=dword:00000000 "Width94"=dword:0000003c "Position95"=dword:00000067 "Visible95"=dword:00000000 "Width95"=dword:0000003c "Position96"=dword:00000068 "Visible96"=dword:00000000 "Width96"=dword:00000046 "Position97"=dword:00000069 "Visible97"=dword:00000000 "Width97"=dword:00000046 "Position98"=dword:0000006a "Visible98"=dword:00000000 "Width98"=dword:00000055 "Position99"=dword:0000006b "Visible99"=dword:00000000 "Width99"=dword:00000073 "Position100"=dword:0000003e "Visible100"=dword:00000000 "Width100"=dword:00000041 "Position101"=dword:0000006c "Visible101"=dword:00000000 "Width101"=dword:0000003c "Position102"=dword:0000006d "Visible102"=dword:00000000 "Width102"=dword:0000003c "Position103"=dword:0000006e "Visible103"=dword:00000000 "Width103"=dword:00000046 "Position104"=dword:0000006f "Visible104"=dword:00000000 "Width104"=dword:0000003c "Position105"=dword:00000070 "Visible105"=dword:00000000 "Width105"=dword:00000041 "Position106"=dword:0000000b "Visible106"=dword:00000001 "Width106"=dword:0000005a "Position107"=dword:00000007 "Visible107"=dword:00000001 "Width107"=dword:00000028 "Position108"=dword:0000003f "Visible108"=dword:00000000 "Width108"=dword:00000050 "Position109"=dword:0000002b "Visible109"=dword:00000000 "Width109"=dword:00000050 "Position110"=dword:0000002d "Visible110"=dword:00000000 "Width110"=dword:00000055 "Position111"=dword:0000002e "Visible111"=dword:00000000 "Width111"=dword:00000082 "Position112"=dword:00000030 "Visible112"=dword:00000000 "Width112"=dword:00000087 "Position113"=dword:00000071 "Visible113"=dword:00000000 "Width113"=dword:00000050 "Position114"=dword:00000072 "Visible114"=dword:00000000 "Width114"=dword:00000050 "Position115"=dword:00000073 "Visible115"=dword:00000000 "Width115"=dword:00000050 "Position116"=dword:00000074 "Visible116"=dword:00000000 "Width116"=dword:00000050 "Position117"=dword:00000075 "Visible117"=dword:00000000 "Width117"=dword:00000050 "Position118"=dword:00000076 "Visible118"=dword:00000000 "Width118"=dword:00000050 "Position119"=dword:00000077 "Visible119"=dword:00000000 "Width119"=dword:00000050 "Position120"=dword:00000078 "Visible120"=dword:00000000 "Width120"=dword:00000050 "Position121"=dword:00000079 "Visible121"=dword:00000000 "Width121"=dword:00000050 "Position122"=dword:0000007a "Visible122"=dword:00000000 "Width122"=dword:00000050 "Position123"=dword:0000007b "Visible123"=dword:00000000 "Width123"=dword:00000050 "Position124"=dword:0000007c "Visible124"=dword:00000000 "Width124"=dword:00000050 "Position125"=dword:0000007d "Visible125"=dword:00000000 "Width125"=dword:00000050 "Position126"=dword:0000007e "Visible126"=dword:00000000 "Width126"=dword:00000050 "Position127"=dword:0000007f "Visible127"=dword:00000000 "Width127"=dword:00000050 "Position128"=dword:00000080 "Visible128"=dword:00000000 "Width128"=dword:00000050 "Position129"=dword:00000081 "Visible129"=dword:00000000 "Width129"=dword:00000050 "Position130"=dword:00000082 "Visible130"=dword:00000000 "Width130"=dword:00000050 "Position131"=dword:00000083 "Visible131"=dword:00000000 "Width131"=dword:00000050 "Position132"=dword:00000084 "Visible132"=dword:00000000 "Width132"=dword:00000050 "Position133"=dword:00000085 "Visible133"=dword:00000000 "Width133"=dword:00000050 "Position134"=dword:00000086 "Visible134"=dword:00000000 "Width134"=dword:00000050 "Position135"=dword:00000087 "Visible135"=dword:00000000 "Width135"=dword:00000050 "Position136"=dword:00000088 "Visible136"=dword:00000000 "Width136"=dword:00000050 "Position137"=dword:00000089 "Visible137"=dword:00000000 "Width137"=dword:00000050 "Position138"=dword:0000008a "Visible138"=dword:00000000 "Width138"=dword:00000050 "Position139"=dword:0000008b "Visible139"=dword:00000000 "Width139"=dword:00000050 "Position140"=dword:0000008c "Visible140"=dword:00000000 "Width140"=dword:00000050 "Position141"=dword:0000008d "Visible141"=dword:00000000 "Width141"=dword:00000050 "Position142"=dword:0000008e "Visible142"=dword:00000000 "Width142"=dword:00000050 "Position143"=dword:0000008f "Visible143"=dword:00000000 "Width143"=dword:00000050 "Position144"=dword:00000090 "Visible144"=dword:00000000 "Width144"=dword:00000050 [HKEY_USERS\S-1-5-21-602162358-1060284298-1202660629-1003\Software\G*e*n*i*e*"!\FM Genie Scout\Columns\Staff] "Position0"=dword:00000000 "Visible0"=dword:00000001 "Width0"=dword:0000007d "Position1"=dword:00000001 "Visible1"=dword:00000001 "Width1"=dword:00000064 "Position2"=dword:00000002 "Visible2"=dword:00000001 "Width2"=dword:00000064 "Position3"=dword:00000003 "Visible3"=dword:00000001 "Width3"=dword:00000069 "Position4"=dword:00000005 "Visible4"=dword:00000001 "Width4"=dword:00000028 "Position5"=dword:00000006 "Visible5"=dword:00000001 "Width5"=dword:00000028 "Position6"=dword:00000004 "Visible6"=dword:00000001 "Width6"=dword:00000028 "Position7"=dword:00000007 "Visible7"=dword:00000001 "Width7"=dword:00000050 "Position8"=dword:00000008 "Visible8"=dword:00000000 "Width8"=dword:00000050 "Position9"=dword:00000009 "Visible9"=dword:00000000 "Width9"=dword:0000004b "Position10"=dword:0000000a "Visible10"=dword:00000000 "Width10"=dword:0000002d "Position11"=dword:0000000b "Visible11"=dword:00000000 "Width11"=dword:0000003c "Position12"=dword:0000000c "Visible12"=dword:00000000 "Width12"=dword:0000004b "Position13"=dword:0000000d "Visible13"=dword:00000000 "Width13"=dword:00000064 "Position14"=dword:0000000e "Visible14"=dword:00000000 "Width14"=dword:00000064 "Position15"=dword:0000000f "Visible15"=dword:00000000 "Width15"=dword:0000004b "Position16"=dword:00000010 "Visible16"=dword:00000000 "Width16"=dword:00000064 "Position17"=dword:00000011 "Visible17"=dword:00000000 "Width17"=dword:0000003c "Position18"=dword:00000012 "Visible18"=dword:00000000 "Width18"=dword:0000004b "Position19"=dword:00000013 "Visible19"=dword:00000000 "Width19"=dword:00000050 "Position20"=dword:00000014 "Visible20"=dword:00000000 "Width20"=dword:00000046 "Position21"=dword:00000015 "Visible21"=dword:00000000 "Width21"=dword:0000004b "Position22"=dword:00000016 "Visible22"=dword:00000000 "Width22"=dword:00000046 "Position23"=dword:00000017 "Visible23"=dword:00000000 "Width23"=dword:00000046 "Position24"=dword:00000018 "Visible24"=dword:00000000 "Width24"=dword:0000003c "Position25"=dword:00000019 "Visible25"=dword:00000000 "Width25"=dword:00000041 "Position26"=dword:0000001a "Visible26"=dword:00000000 "Width26"=dword:0000003c "Position27"=dword:0000001b "Visible27"=dword:00000000 "Width27"=dword:00000055 "Position28"=dword:0000001c "Visible28"=dword:00000000 "Width28"=dword:00000069 "Position29"=dword:0000001d "Visible29"=dword:00000000 "Width29"=dword:0000006e "Position30"=dword:0000001e "Visible30"=dword:00000000 "Width30"=dword:00000064 "Position31"=dword:0000001f "Visible31"=dword:00000000 "Width31"=dword:00000078 "Position32"=dword:00000020 "Visible32"=dword:00000000 "Width32"=dword:00000064 "Position33"=dword:00000021 "Visible33"=dword:00000000 "Width33"=dword:00000087 "Position34"=dword:00000022 "Visible34"=dword:00000000 "Width34"=dword:00000069 "Position35"=dword:00000023 "Visible35"=dword:00000000 "Width35"=dword:0000006e "Position36"=dword:00000024 "Visible36"=dword:00000000 "Width36"=dword:00000073 "Position37"=dword:00000025 "Visible37"=dword:00000000 "Width37"=dword:0000004b "Position38"=dword:00000026 "Visible38"=dword:00000000 "Width38"=dword:0000002d "Position39"=dword:00000027 "Visible39"=dword:00000000 "Width39"=dword:00000055 "Position40"=dword:00000028 "Visible40"=dword:00000000 "Width40"=dword:00000046 "Position41"=dword:00000029 "Visible41"=dword:00000000 "Width41"=dword:0000004b "Position42"=dword:0000002a "Visible42"=dword:00000000 "Width42"=dword:0000003c "Position43"=dword:0000002b "Visible43"=dword:00000000 "Width43"=dword:00000046 "Position44"=dword:0000002c "Visible44"=dword:00000000 "Width44"=dword:00000073 "Position45"=dword:0000002d "Visible45"=dword:00000000 "Width45"=dword:0000004b "Position46"=dword:0000002e "Visible46"=dword:00000000 "Width46"=dword:00000073 "Position47"=dword:0000002f "Visible47"=dword:00000000 "Width47"=dword:0000007d "Position48"=dword:00000030 "Visible48"=dword:00000000 "Width48"=dword:0000006e "Position49"=dword:00000031 "Visible49"=dword:00000000 "Width49"=dword:00000037 "Position50"=dword:00000032 "Visible50"=dword:00000000 "Width50"=dword:00000064 "Position51"=dword:00000033 "Visible51"=dword:00000000 "Width51"=dword:00000037 "Position52"=dword:00000034 "Visible52"=dword:00000000 "Width52"=dword:0000004b "Position53"=dword:00000035 "Visible53"=dword:00000000 "Width53"=dword:00000046 "Position54"=dword:00000036 "Visible54"=dword:00000000 "Width54"=dword:00000037 "Position55"=dword:00000037 "Visible55"=dword:00000000 "Width55"=dword:0000003c "Position56"=dword:00000038 "Visible56"=dword:00000000 "Width56"=dword:00000055 "Position57"=dword:00000039 "Visible57"=dword:00000000 "Width57"=dword:0000003c "Position58"=dword:0000003a "Visible58"=dword:00000000 "Width58"=dword:0000003c "Position59"=dword:0000003b "Visible59"=dword:00000000 "Width59"=dword:00000055 "Position60"=dword:0000003c "Visible60"=dword:00000000 "Width60"=dword:00000046 "Position61"=dword:0000003d "Visible61"=dword:00000000 "Width61"=dword:0000004b "Position62"=dword:0000003e "Visible62"=dword:00000000 "Width62"=dword:00000055 "Position63"=dword:0000003f "Visible63"=dword:00000000 "Width63"=dword:0000005a "Position64"=dword:00000040 "Visible64"=dword:00000000 "Width64"=dword:0000006e "Position65"=dword:00000041 "Visible65"=dword:00000000 "Width65"=dword:00000050 "Position66"=dword:00000042 "Visible66"=dword:00000000 "Width66"=dword:00000032 "Position67"=dword:00000043 "Visible67"=dword:00000000 "Width67"=dword:00000064 "Position68"=dword:00000044 "Visible68"=dword:00000000 "Width68"=dword:0000004b "Position69"=dword:00000045 "Visible69"=dword:00000000 "Width69"=dword:0000002d "Position70"=dword:00000046 "Visible70"=dword:00000000 "Width70"=dword:0000004b "Position71"=dword:00000047 "Visible71"=dword:00000000 "Width71"=dword:0000005a "Position72"=dword:00000048 "Visible72"=dword:00000000 "Width72"=dword:0000005a "Position73"=dword:00000049 "Visible73"=dword:00000000 "Width73"=dword:00000050 "Position74"=dword:0000004a "Visible74"=dword:00000000 "Width74"=dword:0000004b "Position75"=dword:0000004b "Visible75"=dword:00000000 "Width75"=dword:00000050 "Position76"=dword:0000004c "Visible76"=dword:00000000 "Width76"=dword:0000005a "Position77"=dword:0000004d "Visible77"=dword:00000000 "Width77"=dword:00000041 "Position78"=dword:0000004e "Visible78"=dword:00000000 "Width78"=dword:00000041 "Position79"=dword:0000004f "Visible79"=dword:00000000 "Width79"=dword:00000041 "Position80"=dword:00000050 "Visible80"=dword:00000000 "Width80"=dword:00000041 "Position81"=dword:00000051 "Visible81"=dword:00000000 "Width81"=dword:00000041 "Position82"=dword:00000052 "Visible82"=dword:00000000 "Width82"=dword:00000041 "Position83"=dword:00000053 "Visible83"=dword:00000000 "Width83"=dword:00000041 "Position84"=dword:00000054 "Visible84"=dword:00000000 "Width84"=dword:00000041 "Position85"=dword:00000055 "Visible85"=dword:00000000 "Width85"=dword:00000041 [HKEY_USERS\S-1-5-21-602162358-1060284298-1202660629-1003\Software\G*e*n*i*e*"!\FM Genie Scout\Rating] "GKPositionCoef"=dword:00000000 "GKCurrentAbilityCoef"=dword:00000000 "GKCornersCoef"=dword:00000000 "GKCrossingCoef"=dword:00000000 "GKDribblingCoef"=dword:00000000 "GKFinishingCoef"=dword:00000000 "GKFirstTouchCoef"=dword:00000005 "GKFreeKicksCoef"=dword:00000000 "GKHeadingCoef"=dword:00000005 "GKLongShotsCoef"=dword:00000000 "GKLongThrowsCoef"=dword:00000000 "GKMarkingCoef"=dword:00000000 "GKPassingCoef"=dword:0000000a "GKPenaltiesCoef"=dword:00000005 "GKTacklingCoef"=dword:0000000a "GKTechniqueCoef"=dword:00000000 "GKLeftFootCoef"=dword:00000005 "GKRightFootCoef"=dword:00000005 "GKAggressionCoef"=dword:0000001e "GKAnticipationCoef"=dword:0000000a "GKBraveryCoef"=dword:0000001e "GKComposureCoef"=dword:0000001e "GKConcentrationCoef"=dword:00000014 "GKConsistencyCoef"=dword:00000014 "GKCreativityCoef"=dword:00000000 "GKDecisionsCoef"=dword:0000001e "GKDeterminationCoef"=dword:00000014 "GKDirtinessCoef"=dword:fffffff6 "GKFlairCoef"=dword:00000005 "GKImportantMatchesCoef"=dword:00000014 "GKInfluenceCoef"=dword:0000000f "GKOffTheBallCoef"=dword:00000000 "GKPositioningCoef"=dword:0000003c "GKTeamworkCoef"=dword:0000000a "GKWorkRateCoef"=dword:00000005 "GKAccelerationCoef"=dword:0000000a "GKAgilityCoef"=dword:00000014 "GKBalanceCoef"=dword:00000014 "GKInjuryPronenessCoef"=dword:fffffff6 "GKJumpingCoef"=dword:00000050 "GKNaturalFitnessCoef"=dword:0000000a "GKPaceCoef"=dword:00000000 "GKStaminaCoef"=dword:00000005 "GKStrengthCoef"=dword:0000001e "GKVersatilityCoef"=dword:00000005 "GKAerialAbilityCoef"=dword:00000050 "GKCommandOfAreaCoef"=dword:00000032 "GKCommunicationCoef"=dword:0000003c "GKEccentricityCoef"=dword:ffffffe7 "GKHandlingCoef"=dword:00000064 "GKKickingCoef"=dword:00000019 "GKOneOnOnesCoef"=dword:00000032 "GKReflexesCoef"=dword:00000064 "GKRushingOutCoef"=dword:0000001e "GKTendencyToPunchCoef"=dword:ffffffe7 "GKThrowingCoef"=dword:00000019 "GKAdaptabilityCoef"=dword:0000000a "GKAmbitionCoef"=dword:00000014 "GKControversyCoef"=dword:fffffffb "GKLoyalityCoef"=dword:0000000a "GKPressureCoef"=dword:00000014 "GKProfessionalismCoef"=dword:0000000f "GKSportsmanshipCoef"=dword:0000000a "GKTemperamentCoef"=dword:00000005 "SWPositionCoef"=dword:00000000 "SWCurrentAbilityCoef"=dword:00000000 "SWCornersCoef"=dword:0000000a "SWCrossingCoef"=dword:00000005 "SWDribblingCoef"=dword:00000005 "SWFinishingCoef"=dword:00000005 "SWFirstTouchCoef"=dword:00000014 "SWFreeKicksCoef"=dword:0000000a "SWHeadingCoef"=dword:00000064 "SWLongShotsCoef"=dword:00000005 "SWLongThrowsCoef"=dword:00000005 "SWMarkingCoef"=dword:00000064 "SWPassingCoef"=dword:00000014 "SWPenaltiesCoef"=dword:00000005 "SWTacklingCoef"=dword:00000064 "SWTechniqueCoef"=dword:0000000f "SWLeftFootCoef"=dword:0000000a "SWRightFootCoef"=dword:0000000a "SWAggressionCoef"=dword:0000000f "SWAnticipationCoef"=dword:00000014 "SWBraveryCoef"=dword:00000028 "SWComposureCoef"=dword:00000028 "SWConcentrationCoef"=dword:00000028 "SWConsistencyCoef"=dword:00000014 "SWCreativityCoef"=dword:00000005 "SWDecisionsCoef"=dword:0000001e "SWDeterminationCoef"=dword:00000014 "SWDirtinessCoef"=dword:ffffffe7 "SWFlairCoef"=dword:00000005 "SWImportantMatchesCoef"=dword:00000014 "SWInfluenceCoef"=dword:0000000f "SWOffTheBallCoef"=dword:00000005 "SWPositioningCoef"=dword:00000064 "SWTeamworkCoef"=dword:00000028 "SWWorkRateCoef"=dword:0000000a "SWAccelerationCoef"=dword:00000019 "SWAgilityCoef"=dword:00000005 "SWBalanceCoef"=dword:00000014 "SWInjuryPronenessCoef"=dword:fffffff6 "SWJumpingCoef"=dword:00000050 "SWNaturalFitnessCoef"=dword:0000000a "SWPaceCoef"=dword:00000019 "SWStaminaCoef"=dword:0000000f "SWStrengthCoef"=dword:0000003c "SWVersatilityCoef"=dword:00000005 "SWAerialAbilityCoef"=dword:00000000 "SWCommandOfAreaCoef"=dword:00000000 "SWCommunicationCoef"=dword:00000000 "SWEccentricityCoef"=dword:00000000 "SWHandlingCoef"=dword:00000000 "SWKickingCoef"=dword:00000000 "SWOneOnOnesCoef"=dword:00000005 "SWReflexesCoef"=dword:00000005 "SWRushingOutCoef"=dword:00000000 "SWTendencyToPunchCoef"=dword:00000000 "SWThrowingCoef"=dword:00000000 "SWAdaptabilityCoef"=dword:0000000a "SWAmbitionCoef"=dword:00000014 "SWControversyCoef"=dword:fffffffb "SWLoyalityCoef"=dword:0000000a "SWPressureCoef"=dword:00000014 "SWProfessionalismCoef"=dword:0000000f "SWSportsmanshipCoef"=dword:0000000a "SWTemperamentCoef"=dword:00000005 "CBPositionCoef"=dword:00000000 "CBCurrentAbilityCoef"=dword:00000000 "CBCornersCoef"=dword:00000014 "CBCrossingCoef"=dword:0000000a "CBDribblingCoef"=dword:00000005 "CBFinishingCoef"=dword:00000005 "CBFirstTouchCoef"=dword:00000014 "CBFreeKicksCoef"=dword:00000014 "CBHeadingCoef"=dword:00000064 "CBLongShotsCoef"=dword:00000005 "CBLongThrowsCoef"=dword:00000005 "CBMarkingCoef"=dword:00000050 "CBPassingCoef"=dword:0000001e "CBPenaltiesCoef"=dword:00000005 "CBTacklingCoef"=dword:00000064 "CBTechniqueCoef"=dword:0000000f "CBLeftFootCoef"=dword:0000000a "CBRightFootCoef"=dword:0000000a "CBAggressionCoef"=dword:0000000f "CBAnticipationCoef"=dword:00000014 "CBBraveryCoef"=dword:00000028 "CBComposureCoef"=dword:0000001e "CBConcentrationCoef"=dword:0000001e "CBConsistencyCoef"=dword:00000014 "CBCreativityCoef"=dword:00000005 "CBDecisionsCoef"=dword:0000001e "CBDeterminationCoef"=dword:00000014 "CBDirtinessCoef"=dword:ffffffec "CBFlairCoef"=dword:00000005 "CBImportantMatchesCoef"=dword:00000014 "CBInfluenceCoef"=dword:0000000f "CBOffTheBallCoef"=dword:0000000a "CBPositioningCoef"=dword:00000050 "CBTeamworkCoef"=dword:00000028 "CBWorkRateCoef"=dword:0000000a "CBAccelerationCoef"=dword:00000023 "CBAgilityCoef"=dword:00000005 "CBBalanceCoef"=dword:00000014 "CBInjuryPronenessCoef"=dword:fffffff6 "CBJumpingCoef"=dword:00000050 "CBNaturalFitnessCoef"=dword:0000000a "CBPaceCoef"=dword:00000023 "CBStaminaCoef"=dword:00000014 "CBStrengthCoef"=dword:00000032 "CBVersatilityCoef"=dword:00000005 "CBAerialAbilityCoef"=dword:00000000 "CBCommandOfAreaCoef"=dword:00000000 "CBCommunicationCoef"=dword:00000000 "CBEccentricityCoef"=dword:00000000 "CBHandlingCoef"=dword:00000000 "CBKickingCoef"=dword:00000000 "CBOneOnOnesCoef"=dword:00000005 "CBReflexesCoef"=dword:00000005 "CBRushingOutCoef"=dword:00000000 "CBTendencyToPunchCoef"=dword:00000000 "CBThrowingCoef"=dword:00000000 "CBAdaptabilityCoef"=dword:0000000a "CBAmbitionCoef"=dword:00000014 "CBControversyCoef"=dword:fffffffb "CBLoyalityCoef"=dword:0000000a "CBPressureCoef"=dword:00000014 "CBProfessionalismCoef"=dword:0000000f "CBSportsmanshipCoef"=dword:0000000a "CBTemperamentCoef"=dword:00000005 "FBPositionCoef"=dword:00000000 "FBCurrentAbilityCoef"=dword:00000000 "FBCornersCoef"=dword:00000014 "FBCrossingCoef"=dword:00000023 "FBDribblingCoef"=dword:0000001e "FBFinishingCoef"=dword:0000000a "FBFirstTouchCoef"=dword:00000014 "FBFreeKicksCoef"=dword:00000014 "FBHeadingCoef"=dword:0000003c "FBLongShotsCoef"=dword:0000000a "FBLongThrowsCoef"=dword:0000000a "FBMarkingCoef"=dword:00000050 "FBPassingCoef"=dword:00000023 "FBPenaltiesCoef"=dword:00000005 "FBTacklingCoef"=dword:00000064 "FBTechniqueCoef"=dword:0000001e "FBLeftFootCoef"=dword:0000000a "FBRightFootCoef"=dword:0000000a "FBAggressionCoef"=dword:0000000f "FBAnticipationCoef"=dword:0000003c "FBBraveryCoef"=dword:00000019 "FBComposureCoef"=dword:00000019 "FBConcentrationCoef"=dword:0000001e "FBConsistencyCoef"=dword:00000014 "FBCreativityCoef"=dword:0000000a "FBDecisionsCoef"=dword:00000019 "FBDeterminationCoef"=dword:00000014 "FBDirtinessCoef"=dword:fffffff1 "FBFlairCoef"=dword:00000005 "FBImportantMatchesCoef"=dword:00000014 "FBInfluenceCoef"=dword:0000000f "FBOffTheBallCoef"=dword:0000000f "FBPositioningCoef"=dword:00000050 "FBTeamworkCoef"=dword:00000014 "FBWorkRateCoef"=dword:00000014 "FBAccelerationCoef"=dword:00000032 "FBAgilityCoef"=dword:00000005 "FBBalanceCoef"=dword:00000014 "FBInjuryPronenessCoef"=dword:fffffff6 "FBJumpingCoef"=dword:0000003c "FBNaturalFitnessCoef"=dword:0000000a "FBPaceCoef"=dword:00000032 "FBStaminaCoef"=dword:0000001e "FBStrengthCoef"=dword:00000028 "FBVersatilityCoef"=dword:00000005 "FBAerialAbilityCoef"=dword:00000000 "FBCommandOfAreaCoef"=dword:00000000 "FBCommunicationCoef"=dword:00000000 "FBEccentricityCoef"=dword:00000000 "FBHandlingCoef"=dword:00000000 "FBKickingCoef"=dword:00000000 "FBOneOnOnesCoef"=dword:00000005 "FBReflexesCoef"=dword:00000005 "FBRushingOutCoef"=dword:00000000 "FBTendencyToPunchCoef"=dword:00000000 "FBThrowingCoef"=dword:00000000 "FBAdaptabilityCoef"=dword:0000000a "FBAmbitionCoef"=dword:00000014 "FBControversyCoef"=dword:fffffffb "FBLoyalityCoef"=dword:0000000a "FBPressureCoef"=dword:00000014 "FBProfessionalismCoef"=dword:0000000f "FBSportsmanshipCoef"=dword:0000000a "FBTemperamentCoef"=dword:00000005 "WBPositionCoef"=dword:00000000 "WBCurrentAbilityCoef"=dword:00000000 "WBCornersCoef"=dword:00000014 "WBCrossingCoef"=dword:0000004b "WBDribblingCoef"=dword:0000003c "WBFinishingCoef"=dword:0000001e "WBFirstTouchCoef"=dword:00000019 "WBFreeKicksCoef"=dword:00000014 "WBHeadingCoef"=dword:00000019 "WBLongShotsCoef"=dword:0000000f "WBLongThrowsCoef"=dword:0000000f "WBMarkingCoef"=dword:0000003c "WBPassingCoef"=dword:00000028 "WBPenaltiesCoef"=dword:00000005 "WBTacklingCoef"=dword:00000050 "WBTechniqueCoef"=dword:00000032 "WBLeftFootCoef"=dword:0000000a "WBRightFootCoef"=dword:0000000a "WBAggressionCoef"=dword:0000000a "WBAnticipationCoef"=dword:00000032 "WBBraveryCoef"=dword:0000000f "WBComposureCoef"=dword:00000014 "WBConcentrationCoef"=dword:00000019 "WBConsistencyCoef"=dword:00000014 "WBCreativityCoef"=dword:00000014 "WBDecisionsCoef"=dword:00000014 "WBDeterminationCoef"=dword:00000014 "WBDirtinessCoef"=dword:fffffff6 "WBFlairCoef"=dword:0000000a "WBImportantMatchesCoef"=dword:00000014 "WBInfluenceCoef"=dword:0000000a "WBOffTheBallCoef"=dword:00000014 "WBPositioningCoef"=dword:0000003c "WBTeamworkCoef"=dword:00000014 "WBWorkRateCoef"=dword:0000001e "WBAccelerationCoef"=dword:00000050 "WBAgilityCoef"=dword:00000005 "WBBalanceCoef"=dword:0000000f "WBInjuryPronenessCoef"=dword:fffffff6 "WBJumpingCoef"=dword:00000019 "WBNaturalFitnessCoef"=dword:0000000a "WBPaceCoef"=dword:0000005a "WBStaminaCoef"=dword:0000004b "WBStrengthCoef"=dword:00000028 "WBVersatilityCoef"=dword:00000005 "WBAerialAbilityCoef"=dword:00000000 "WBCommandOfAreaCoef"=dword:00000000 "WBCommunicationCoef"=dword:00000000 "WBEccentricityCoef"=dword:00000000 "WBHandlingCoef"=dword:00000000 "WBKickingCoef"=dword:00000000 "WBOneOnOnesCoef"=dword:00000005 "WBReflexesCoef"=dword:00000005 "WBRushingOutCoef"=dword:00000000 "WBTendencyToPunchCoef"=dword:00000000 "WBThrowingCoef"=dword:00000000 "WBAdaptabilityCoef"=dword:0000000a "WBAmbitionCoef"=dword:00000014 "WBControversyCoef"=dword:fffffffb "WBLoyalityCoef"=dword:0000000a "WBPressureCoef"=dword:00000014 "WBProfessionalismCoef"=dword:0000000f "WBSportsmanshipCoef"=dword:0000000a "WBTemperamentCoef"=dword:00000005 "DMPositionCoef"=dword:00000000 "DMCurrentAbilityCoef"=dword:00000000 "DMCornersCoef"=dword:00000014 "DMCrossingCoef"=dword:00000028 "DMDribblingCoef"=dword:00000019 "DMFinishingCoef"=dword:0000001e "DMFirstTouchCoef"=dword:00000019 "DMFreeKicksCoef"=dword:00000014 "DMHeadingCoef"=dword:00000032 "DMLongShotsCoef"=dword:00000014 "DMLongThrowsCoef"=dword:0000000a "DMMarkingCoef"=dword:0000004b "DMPassingCoef"=dword:00000032 "DMPenaltiesCoef"=dword:00000005 "DMTacklingCoef"=dword:00000050 "DMTechniqueCoef"=dword:0000001e "DMLeftFootCoef"=dword:0000000a "DMRightFootCoef"=dword:0000000a "DMAggressionCoef"=dword:00000028 "DMAnticipationCoef"=dword:00000028 "DMBraveryCoef"=dword:0000000f "DMComposureCoef"=dword:00000014 "DMConcentrationCoef"=dword:00000019 "DMConsistencyCoef"=dword:00000014 "DMCreativityCoef"=dword:00000019 "DMDecisionsCoef"=dword:00000014 "DMDeterminationCoef"=dword:00000014 "DMDirtinessCoef"=dword:fffffff6 "DMFlairCoef"=dword:0000000f "DMImportantMatchesCoef"=dword:00000014 "DMInfluenceCoef"=dword:0000000f "DMOffTheBallCoef"=dword:00000019 "DMPositioningCoef"=dword:0000003c "DMTeamworkCoef"=dword:0000001e "DMWorkRateCoef"=dword:0000003c "DMAccelerationCoef"=dword:00000028 "DMAgilityCoef"=dword:00000005 "DMBalanceCoef"=dword:0000000f "DMInjuryPronenessCoef"=dword:fffffff6 "DMJumpingCoef"=dword:00000028 "DMNaturalFitnessCoef"=dword:0000000a "DMPaceCoef"=dword:00000023 "DMStaminaCoef"=dword:00000041 "DMStrengthCoef"=dword:00000032 "DMVersatilityCoef"=dword:00000005 "DMAerialAbilityCoef"=dword:00000000 "DMCommandOfAreaCoef"=dword:00000000 "DMCommunicationCoef"=dword:00000000 "DMEccentricityCoef"=dword:00000000 "DMHandlingCoef"=dword:00000000 "DMKickingCoef"=dword:00000000 "DMOneOnOnesCoef"=dword:00000005 "DMReflexesCoef"=dword:00000005 "DMRushingOutCoef"=dword:00000000 "DMTendencyToPunchCoef"=dword:00000000 "DMThrowingCoef"=dword:00000000 "DMAdaptabilityCoef"=dword:0000000a "DMAmbitionCoef"=dword:00000014 "DMControversyCoef"=dword:fffffffb "DMLoyalityCoef"=dword:0000000a "DMPressureCoef"=dword:00000014 "DMProfessionalismCoef"=dword:0000000f "DMSportsmanshipCoef"=dword:0000000a "DMTemperamentCoef"=dword:00000005 "MPositionCoef"=dword:00000000 "MCurrentAbilityCoef"=dword:00000000 "MCornersCoef"=dword:00000019 "MCrossingCoef"=dword:00000032 "MDribblingCoef"=dword:00000032 "MFinishingCoef"=dword:00000028 "MFirstTouchCoef"=dword:0000001e "MFreeKicksCoef"=dword:00000014 "MHeadingCoef"=dword:00000028 "MLongShotsCoef"=dword:00000019 "MLongThrowsCoef"=dword:0000000a "MMarkingCoef"=dword:00000028 "MPassingCoef"=dword:0000004b "MPenaltiesCoef"=dword:00000005 "MTacklingCoef"=dword:00000028 "MTechniqueCoef"=dword:00000032 "MLeftFootCoef"=dword:0000000a "MRightFootCoef"=dword:0000000a "MAggressionCoef"=dword:0000001e "MAnticipationCoef"=dword:00000028 "MBraveryCoef"=dword:0000000a "MComposureCoef"=dword:00000014 "MConcentrationCoef"=dword:00000014 "MConsistencyCoef"=dword:00000014 "MCreativityCoef"=dword:0000003c "MDecisionsCoef"=dword:00000014 "MDeterminationCoef"=dword:00000014 "MDirtinessCoef"=dword:fffffffb "MFlairCoef"=dword:00000014 "MImportantMatchesCoef"=dword:00000014 "MInfluenceCoef"=dword:0000000a "MOffTheBallCoef"=dword:0000001e "MPositioningCoef"=dword:00000028 "MTeamworkCoef"=dword:00000023 "MWorkRateCoef"=dword:00000032 "MAccelerationCoef"=dword:0000002d "MAgilityCoef"=dword:00000005 "MBalanceCoef"=dword:0000000a "MInjuryPronenessCoef"=dword:fffffff6 "MJumpingCoef"=dword:0000001e "MNaturalFitnessCoef"=dword:0000000a "MPaceCoef"=dword:00000028 "MStaminaCoef"=dword:0000003c "MStrengthCoef"=dword:00000023 "MVersatilityCoef"=dword:00000005 "MAerialAbilityCoef"=dword:00000000 "MCommandOfAreaCoef"=dword:00000000 "MCommunicationCoef"=dword:00000000 "MEccentricityCoef"=dword:00000000 "MHandlingCoef"=dword:00000000 "MKickingCoef"=dword:00000000 "MOneOnOnesCoef"=dword:00000005 "MReflexesCoef"=dword:00000005 "MRushingOutCoef"=dword:00000000 "MTendencyToPunchCoef"=dword:00000000 "MThrowingCoef"=dword:00000000 "MAdaptabilityCoef"=dword:0000000a "MAmbitionCoef"=dword:00000014 "MControversyCoef"=dword:fffffffb "MLoyalityCoef"=dword:0000000a "MPressureCoef"=dword:00000014 "MProfessionalismCoef"=dword:0000000f "MSportsmanshipCoef"=dword:0000000a "MTemperamentCoef"=dword:00000005 "AMPositionCoef"=dword:00000000 "AMCurrentAbilityCoef"=dword:00000000 "AMCornersCoef"=dword:00000019 "AMCrossingCoef"=dword:00000046 "AMDribblingCoef"=dword:00000046 "AMFinishingCoef"=dword:00000032 "AMFirstTouchCoef"=dword:00000028 "AMFreeKicksCoef"=dword:00000014 "AMHeadingCoef"=dword:0000001e "AMLongShotsCoef"=dword:0000001e "AMLongThrowsCoef"=dword:00000005 "AMMarkingCoef"=dword:0000000f "AMPassingCoef"=dword:00000064 "AMPenaltiesCoef"=dword:00000005 "AMTacklingCoef"=dword:0000000a "AMTechniqueCoef"=dword:00000050 "AMLeftFootCoef"=dword:0000000a "AMRightFootCoef"=dword:0000000a "AMAggressionCoef"=dword:0000000a "AMAnticipationCoef"=dword:00000023 "AMBraveryCoef"=dword:0000000a "AMComposureCoef"=dword:00000014 "AMConcentrationCoef"=dword:00000014 "AMConsistencyCoef"=dword:00000014 "AMCreativityCoef"=dword:00000064 "AMDecisionsCoef"=dword:00000014 "AMDeterminationCoef"=dword:00000014 "AMDirtinessCoef"=dword:fffffffb "AMFlairCoef"=dword:0000001e "AMImportantMatchesCoef"=dword:00000014 "AMInfluenceCoef"=dword:0000000a "AMOffTheBallCoef"=dword:00000028 "AMPositioningCoef"=dword:00000014 "AMTeamworkCoef"=dword:00000028 "AMWorkRateCoef"=dword:00000019 "AMAccelerationCoef"=dword:00000032 "AMAgilityCoef"=dword:0000000a "AMBalanceCoef"=dword:0000000a "AMInjuryPronenessCoef"=dword:fffffff6 "AMJumpingCoef"=dword:00000014 "AMNaturalFitnessCoef"=dword:0000000a "AMPaceCoef"=dword:00000032 "AMStaminaCoef"=dword:00000028 "AMStrengthCoef"=dword:00000014 "AMVersatilityCoef"=dword:00000005 "AMAerialAbilityCoef"=dword:00000000 "AMCommandOfAreaCoef"=dword:00000000 "AMCommunicationCoef"=dword:00000000 "AMEccentricityCoef"=dword:00000000 "AMHandlingCoef"=dword:00000000 "AMKickingCoef"=dword:00000000 "AMOneOnOnesCoef"=dword:00000005 "AMReflexesCoef"=dword:00000005 "AMRushingOutCoef"=dword:00000000 "AMTendencyToPunchCoef"=dword:00000000 "AMThrowingCoef"=dword:00000000 "AMAdaptabilityCoef"=dword:0000000a "AMAmbitionCoef"=dword:00000014 "AMControversyCoef"=dword:fffffffb "AMLoyalityCoef"=dword:0000000a "AMPressureCoef"=dword:00000014 "AMProfessionalismCoef"=dword:0000000f "AMSportsmanshipCoef"=dword:0000000a "AMTemperamentCoef"=dword:00000005 "WPositionCoef"=dword:00000000 "WCurrentAbilityCoef"=dword:00000000 "WCornersCoef"=dword:00000019 "WCrossingCoef"=dword:00000064 "WDribblingCoef"=dword:00000064 "WFinishingCoef"=dword:0000003c "WFirstTouchCoef"=dword:0000001e "WFreeKicksCoef"=dword:00000014 "WHeadingCoef"=dword:00000014 "WLongShotsCoef"=dword:00000019 "WLongThrowsCoef"=dword:0000000a "WMarkingCoef"=dword:00000019 "WPassingCoef"=dword:0000003c "WPenaltiesCoef"=dword:00000005 "WTacklingCoef"=dword:00000014 "WTechniqueCoef"=dword:00000050 "WLeftFootCoef"=dword:0000000a "WRightFootCoef"=dword:0000000a "WAggressionCoef"=dword:0000000a "WAnticipationCoef"=dword:00000023 "WBraveryCoef"=dword:0000000a "WComposureCoef"=dword:00000014 "WConcentrationCoef"=dword:00000014 "WConsistencyCoef"=dword:00000014 "WCreativityCoef"=dword:00000032 "WDecisionsCoef"=dword:0000000f "WDeterminationCoef"=dword:00000014 "WDirtinessCoef"=dword:fffffffb "WFlairCoef"=dword:0000001e "WImportantMatchesCoef"=dword:00000014 "WInfluenceCoef"=dword:00000005 "WOffTheBallCoef"=dword:00000032 "WPositioningCoef"=dword:00000019 "WTeamworkCoef"=dword:0000001e "WWorkRateCoef"=dword:0000001e "WAccelerationCoef"=dword:00000050 "WAgilityCoef"=dword:00000014 "WBalanceCoef"=dword:0000000a "WInjuryPronenessCoef"=dword:fffffff6 "WJumpingCoef"=dword:00000014 "WNaturalFitnessCoef"=dword:0000000a "WPaceCoef"=dword:00000064 "WStaminaCoef"=dword:00000032 "WStrengthCoef"=dword:00000014 "WVersatilityCoef"=dword:00000005 "WAerialAbilityCoef"=dword:00000000 "WCommandOfAreaCoef"=dword:00000000 "WCommunicationCoef"=dword:00000000 "WEccentricityCoef"=dword:00000000 "WHandlingCoef"=dword:00000000 "WKickingCoef"=dword:00000000 "WOneOnOnesCoef"=dword:00000005 "WReflexesCoef"=dword:00000005 "WRushingOutCoef"=dword:00000000 "WTendencyToPunchCoef"=dword:00000000 "WThrowingCoef"=dword:00000000 "WAdaptabilityCoef"=dword:0000000a "WAmbitionCoef"=dword:00000014 "WControversyCoef"=dword:fffffffb "WLoyalityCoef"=dword:0000000a "WPressureCoef"=dword:00000014 "WProfessionalismCoef"=dword:0000000f "WSportsmanshipCoef"=dword:0000000a "WTemperamentCoef"=dword:00000005 "FSTPositionCoef"=dword:00000000 "FSTCurrentAbilityCoef"=dword:00000000 "FSTCornersCoef"=dword:00000014 "FSTCrossingCoef"=dword:0000001e "FSTDribblingCoef"=dword:00000050 "FSTFinishingCoef"=dword:00000064 "FSTFirstTouchCoef"=dword:00000028 "FSTFreeKicksCoef"=dword:00000014 "FSTHeadingCoef"=dword:0000003c "FSTLongShotsCoef"=dword:0000001e "FSTLongThrowsCoef"=dword:00000005 "FSTMarkingCoef"=dword:0000000a "FSTPassingCoef"=dword:00000028 "FSTPenaltiesCoef"=dword:00000005 "FSTTacklingCoef"=dword:0000000a "FSTTechniqueCoef"=dword:0000004b "FSTLeftFootCoef"=dword:0000000a "FSTRightFootCoef"=dword:0000000a "FSTAggressionCoef"=dword:00000014 "FSTAnticipationCoef"=dword:00000014 "FSTBraveryCoef"=dword:0000000f "FSTComposureCoef"=dword:00000014 "FSTConcentrationCoef"=dword:00000014 "FSTConsistencyCoef"=dword:00000014 "FSTCreativityCoef"=dword:00000032 "FSTDecisionsCoef"=dword:0000000a "FSTDeterminationCoef"=dword:00000014 "FSTDirtinessCoef"=dword:fffffffb "FSTFlairCoef"=dword:00000019 "FSTImportantMatchesCoef"=dword:00000014 "FSTInfluenceCoef"=dword:00000005 "FSTOffTheBallCoef"=dword:0000003c "FSTPositioningCoef"=dword:0000000a "FSTTeamworkCoef"=dword:0000000a "FSTWorkRateCoef"=dword:0000000a "FSTAccelerationCoef"=dword:00000064 "FSTAgilityCoef"=dword:0000001e "FSTBalanceCoef"=dword:00000014 "FSTInjuryPronenessCoef"=dword:fffffff6 "FSTJumpingCoef"=dword:00000014 "FSTNaturalFitnessCoef"=dword:0000000a "FSTPaceCoef"=dword:0000005a "FSTStaminaCoef"=dword:00000014 "FSTStrengthCoef"=dword:00000014 "FSTVersatilityCoef"=dword:00000005 "FSTAerialAbilityCoef"=dword:00000000 "FSTCommandOfAreaCoef"=dword:00000000 "FSTCommunicationCoef"=dword:00000000 "FSTEccentricityCoef"=dword:00000000 "FSTHandlingCoef"=dword:00000000 "FSTKickingCoef"=dword:00000000 "FSTOneOnOnesCoef"=dword:00000005 "FSTReflexesCoef"=dword:00000005 "FSTRushingOutCoef"=dword:00000000 "FSTTendencyToPunchCoef"=dword:00000000 "FSTThrowingCoef"=dword:00000000 "FSTAdaptabilityCoef"=dword:0000000a "FSTAmbitionCoef"=dword:00000014 "FSTControversyCoef"=dword:fffffffb "FSTLoyalityCoef"=dword:0000000a "FSTPressureCoef"=dword:00000014 "FSTProfessionalismCoef"=dword:0000000f "FSTSportsmanshipCoef"=dword:0000000a "FSTTemperamentCoef"=dword:00000005 "TSTPositionCoef"=dword:00000000 "TSTCurrentAbilityCoef"=dword:00000000 "TSTCornersCoef"=dword:00000014 "TSTCrossingCoef"=dword:0000001e "TSTDribblingCoef"=dword:0000003c "TSTFinishingCoef"=dword:0000003c "TSTFirstTouchCoef"=dword:00000028 "TSTFreeKicksCoef"=dword:00000014 "TSTHeadingCoef"=dword:00000064 "TSTLongShotsCoef"=dword:0000001e "TSTLongThrowsCoef"=dword:00000005 "TSTMarkingCoef"=dword:0000000a "TSTPassingCoef"=dword:0000001e "TSTPenaltiesCoef"=dword:00000005 "TSTTacklingCoef"=dword:0000000a "TSTTechniqueCoef"=dword:00000028 "TSTLeftFootCoef"=dword:0000000a "TSTRightFootCoef"=dword:0000000a "TSTAggressionCoef"=dword:00000014 "TSTAnticipationCoef"=dword:00000014 "TSTBraveryCoef"=dword:00000014 "TSTComposureCoef"=dword:00000014 "TSTConcentrationCoef"=dword:00000014 "TSTConsistencyCoef"=dword:00000014 "TSTCreativityCoef"=dword:00000028 "TSTDecisionsCoef"=dword:0000000a "TSTDeterminationCoef"=dword:00000014 "TSTDirtinessCoef"=dword:fffffffb "TSTFlairCoef"=dword:00000019 "TSTImportantMatchesCoef"=dword:00000014 "TSTInfluenceCoef"=dword:00000005 "TSTOffTheBallCoef"=dword:00000050 "TSTPositioningCoef"=dword:0000000a "TSTTeamworkCoef"=dword:0000000a "TSTWorkRateCoef"=dword:0000000a "TSTAccelerationCoef"=dword:00000028 "TSTAgilityCoef"=dword:00000014 "TSTBalanceCoef"=dword:00000014 "TSTInjuryPronenessCoef"=dword:fffffff6 "TSTJumpingCoef"=dword:00000064 "TSTNaturalFitnessCoef"=dword:0000000a "TSTPaceCoef"=dword:00000023 "TSTStaminaCoef"=dword:0000000f "TSTStrengthCoef"=dword:00000050 "TSTVersatilityCoef"=dword:00000005 "TSTAerialAbilityCoef"=dword:00000000 "TSTCommandOfAreaCoef"=dword:00000000 "TSTCommunicationCoef"=dword:00000000 "TSTEccentricityCoef"=dword:00000000 "TSTHandlingCoef"=dword:00000000 "TSTKickingCoef"=dword:00000000 "TSTOneOnOnesCoef"=dword:00000005 "TSTReflexesCoef"=dword:00000005 "TSTRushingOutCoef"=dword:00000000 "TSTTendencyToPunchCoef"=dword:00000000 "TSTThrowingCoef"=dword:00000000 "TSTAdaptabilityCoef"=dword:0000000a "TSTAmbitionCoef"=dword:00000014 "TSTControversyCoef"=dword:fffffffb "TSTLoyalityCoef"=dword:0000000a "TSTPressureCoef"=dword:00000014 "TSTProfessionalismCoef"=dword:0000000f "TSTSportsmanshipCoef"=dword:0000000a "TSTTemperamentCoef"=dword:00000005 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*] "OODEFRAG08.00.00.01WORKSTATION"="8180AC66A30F66398D79CC55AA40C5F3373699DBDB2BA53BEAD482D996BD879B414D7879E34 2EEEC0BB225896EE24629378873E6544D895F1026E8E93F54C83132234F754F317C5E6CE1A90C5F4 9 9DEA5D1D7F70890CA0426A09F5640ADAAD81078BB5E86486B23E42F925976655C867B16D6F877223 5 D34242360489B863921A4F38861138FCC01CFCF376C618D5396F75847BD79F1BF4C1C7BB0970DAE8 3 FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C F EBC9E127BECC74C8EDD5E5BE2F6E6678EDD5E5BE2F6E667A6A0AC4980AC7933A9C6AECB7A5D1407D E 81C55C843BF6A1CFA31D5663D59A7CFDA1AC15BB039EC73C9769E0BD0F099BB9A09B94B577A6512C C 686324DC27346125195CC46AF1368044EA0BFD92FE09B8B7E41B999B6036618862F916BD31B74FCF 4 BBF407A07DE67915C9D898FB7D7462156AC6DA984459C3F87676D8D6C397ABE04734AB72250A6F1D F 71755FEDD420E10338EA636453A20E61FB6B511BE54521B45056236F6AAF6C89D3A7137AAB325CF1 B B32E1A842D634E517BA2BA8661685E26355FF104B5EBAF965752162B8801E982B02744A4E707DF97 4 24800B58C29183E695B1E01ABE79E9ED4DE01CF993EA531D14BA6EC384B82625D4E800CB6136DC51 7 102847244B9358EF83D3A9D03D00CFB6D8A7487A2F4F047267CFECD06832D989BDEF5346BAC2C736 3 3DA6DAAA42A6F55102345A37C14B4FB4377E16733F1F8DEA84B46501F13580D61D8763BDB0880773 8 6896BABA50104719F01694BB6B090B1803649323A1D52C0703C1A792B15AB79A3A155BB8BB14F425 A F59879390D2D3D75498F338BD721F1F84712C3773B68784CF39330940A57D231420868B090155B77 0 EC6D11E843462D7BCB9480CF34AC4653A20781780CA7D7F80169BB2E25FC8B7B148A275C41D33379 3 AC4677955BF38E4952F3C39F0930A29B81C008EB40E2910636EB6034AD1BB04CBB1A95A002CB2977 6 93180766B08464A69F77ED071EEE3AD14D3F7C20995295B067C50E7F349270D2B6B5995E47145F50 8 604C1D69ABA7A7E70041D675C871C3F8284E481EBBA6DD72BFCE0AF6F8C425BF94E34C7BFF0C629B 6 8EEAA91D717AF2B66CE2983B11FA589616FD1797C4281538BFA5DBA1F808B68FABA3D53526056748 4 CC2BC61FD7E4CB57144338197A2ED8D09A67C273E9A2F8069B3BA4EC507601434EE456C6F4D4E574 0 408743623478E11C7EF58AB050C1A39D4190EAEDBEC107F888724357B21D5FF72D7B4689556C2CB1 2 778D9C3ECBD265F236DDB445C18A2B5E4671D2CEE9BC4537E5A47F1F2A7F74450987A6F2C18488BE 3 52C9F1888F7EC50CA988E53250915057D3D908EB286612DB4E202FB7E960C2441D32245B7A454AB9 2 2E483A7E6E6B113FAE2B89492AB9F" . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'explorer.exe'(2656) c:\windows\system32\WININET.dll c:\arquivos de programas\RocketDock\RocketDock.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\arquivos de programas\LAVASOFT\AD-AWARE\AAWSERVICE.EXE c:\arquivos de programas\AVIRA\ANTIVIR DESKTOP\AVGUARD.EXE c:\arquivos de programas\BONJOUR\MDNSRESPONDER.EXE c:\arquivos de programas\ARQUIVOS COMUNS\MICROSOFT SHARED\VS7DEBUG\MDM.EXE c:\arquivos de programas\ARQUIVOS COMUNS\NERO\NERO BACKITUP 4\NBSERVICE.EXE c:\arquivos de programas\SPEEDBIT VIDEO ACCELERATOR\VIDEOACCELERATORSERVICE.EXE c:\windows\SYSTEM32\WBEM\UNSECAPP.EXE c:\arquivos de programas\SPEEDBIT VIDEO ACCELERATOR\VIDEOACCELERATORENGINE.EXE . ************************************************************************** . Tempo para conclusão: 2009-06-26 17:13 - Máquina reiniciou ComboFix-quarantined-files.txt 2009-06-26 20:13 Pré-execução: 12 pasta(s) 13.867.450.368 bytes disponíveis Pós execução: 12 pasta(s) 13.756.301.312 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin 1675 --- E O F --- 2009-06-24 06:04 e o novo log do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:48:07, on 26/6/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\RocketDock\RocketDock.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\svchost.exe G:\opera.exe C:\Documents and Settings\administrator\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe" O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: windows_system_32-dll.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) - O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} - O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - (no file) O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - (no file) O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe -- End of file - 7999 bytes Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Junho 26, 2009 :thumbsup: Mais outros problemas foram removidos pelo Combofix. :seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: - Faça o download do Malwarebytes Anti-Malware. * Faça a instalação dando um duplo clique em "mbam-setup.exe"; *Selecione a linguagem Português (Brasil) *Selecione apenas a caixa: "Atualizar MalwareBytes'Anti-Malware" *Se alguma atualização existir, o download será automático *Não faça ainda scan!!! *Reinicie o PC em Modo de Segurança (apertando a tecla F8 (ou a tecla F5 em alguns computadores) repetidas vezes quando o computador estiver reiniciando e escolhendo a opção Modo Seguro ou Modo de Segurança). * Se não possível executar o computador em Modo Seguro, faça o escaneamento no modo normal *Execute o programa MalwareBytes'Anti-Malware e clique na aba: "Verificação", selecione a opção "Verificação completa" *Clique no botão: "Verificar" * Marque todas as partes do computador que você deseja escanear e clique no botão: “Iniciar verificação” *Ao término do scan, clique em "OK" > "Mostrar Resultados" *Selecione todas as entradas e clique em "Remover Selecionados" *Após a remoção poderá ser interrogado se deseja remover objetos da memória. Clique "SIM" *Um log será apresentado com o resultado das ações *Alguns malwares são rebeldes e necessitam de uma reinicialização para a remoção. Caso isto seja solicitado, clique para reiniciar o PC. *Ao término do processo, reinicie o PC em Modo Normal. * Depois de alguns dias, se o seu computador estiver funcionando normalmente sem estes arquivos que foram excluidos pelo Malwarebytes Anti-malware, abra (execute) o Malwarebytes Anti-malware, clique na aba: Quarentena e clique no botão: Remover tudo. *Execute novamente o programa Malwarebytes Anti-malware e clique na aba “Logs”, dê um duplo clique com o mouse sobre o log mais recente, selecione o log completo e copie-o. Poste este log gerado pelo Malwarebytes Anti-Malware juntamente com um novo log do Hijackthis na sua próxima resposta e nos diga como está o seu computador depois de seguir este procedimento acima. Ficamos no aguardo de sua resposta. Compartilhar este post Link para o post Compartilhar em outros sites
Paulo. 0 Denunciar post Postado Junho 27, 2009 A janelinha ainda continua infelizmente aparecendo ! Mas aqui estão os logs: log do Malwarebytes Anti-Malware: Malwarebytes' Anti-Malware 1.38 Versão do banco de dados: 2340 Windows 5.1.2600 Service Pack 2 26/6/2009 20:52:37 mbam-log-2009-06-26 (20-52-37).txt Tipo de Verificação: Completa (C:\|G:\|) Objetos verificados: 271665 Tempo decorrido: 1 hour(s), 16 minute(s), 33 second(s) Processos da Memória infectados: 0 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 3 Valores do Registro infectados: 0 Ítens do Registro infectados: 2 Pastas infectadas: 8 Arquivos infectados: 3 Processos da Memória infectados: (Nenhum ítem malicioso foi detectado) Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: HKEY_LOCAL_MACHINE\SOFTWARE\Miracle (Rogue.PerfectOptimizer) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\.pox (Rogue.FixTool) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\pofile (Rogue.FixTool) -> Quarantined and deleted successfully. Valores do Registro infectados: (Nenhum ítem malicioso foi detectado) Ítens do Registro infectados: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Pastas infectadas: C:\Arquivos de programas\Perfect Optimizer (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully. c:\arquivos de programas\perfect optimizer\Backup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully. c:\arquivos de programas\perfect optimizer\Backup\Registry (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully. c:\arquivos de programas\perfect optimizer\Backup\Registry\FirstBackup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully. c:\arquivos de programas\perfect optimizer\Backup\Registry\FullBackup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully. c:\arquivos de programas\perfect optimizer\Backup\Service (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully. c:\arquivos de programas\perfect optimizer\Backup\Application (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully. c:\arquivos de programas\perfect optimizer\Temp (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully. Arquivos infectados: c:\system volume information\_restore{c2768274-003b-4719-a76c-5e22b1965b5a}\RP775\A0113213.exe (Rogue.PerfectOptimizer) -> Quarantined and deleted successfully. g:\system volume information\_restore{c2768274-003b-4719-a76c-5e22b1965b5a}\RP753\A0109759.exe (Rogue.Installer) -> Quarantined and deleted successfully. c:\arquivos de programas\perfect optimizer\PerfectOptimizer.ini (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully. e o novo log do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:30:44, on 27/6/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\RocketDock\RocketDock.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe G:\opera.exe C:\Documents and Settings\administrator\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe" O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: windows_system_32-dll.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) - O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} - O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - (no file) O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - (no file) O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe -- End of file - 7966 bytes Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Junho 27, 2009 :thumbsup: Mais 16 problemas foram removidos pelo Malwarebytes. :seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: - Faça o download do SmitfraudFix. Desabilite temporariamente seu anti vírus. Extraia os arquivos para o seu desktop (área de trabalho). Reinicie o computador apertando intermitentemente F8 (ou a tecla F5 em alguns computares) e escolha modo seguro (ou modo de segurança). * Se não possível executar o computador em Modo Seguro, faça o escaneamento no modo normal. Entre na pasta criada pelo Smitfraudfix e dê um duplo-clique em Smitfraudfix. Pressione qualquer tecla para iniciá-lo. Selecione a opção 2 e tecle enter. Ao perguntar se quer limpar o Registro, dê o Sim ( y ). Reinicie o computador em modo normal e ative novamente a proteção do seu antivírus. _____________________________________________________________________________ :seta: Siga também, por gentileza, as dicas deste tutorial para fazer um escaneamento de seu PC pelo Nod32 Online: Tutorial do antivirus Nod32 Online Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador: C:\Arquivos de programas\EsetOnlineScanner\log Na sua próxima resposta poste este log do Nod32 Online juntamente com o log do SmitFraudFix (rapport.txt ), que se encontrará em C:\ e também um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir estes procedimentos. Ficamos no aguardo de sua resposta. Compartilhar este post Link para o post Compartilhar em outros sites
Paulo. 0 Denunciar post Postado Junho 28, 2009 Ainda continua aparecendo a janela Autolt Error infelizmente :unsure: foto:http://img10.imageshack.us/img10/9438/imagemuem.jpg Como dito, essa janela só aparece ao iniciar o pc, mas eu percebi que o pc fica um pouco lento até aparecer essa janela, mas depois de clicar no Ok o pc volta ao normal :thumbsup: Mas aqui estão os logs: log do Nod32 Online: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.5863 # api_version=3.0.2 # EOSSerial=008f4a627e4d024db63c1c5c9699d812 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-06-27 11:56:52 # local_time=2009-06-27 08:56:52 (-0300, Hora oficial do Brasil) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=1797 37 100 100 936403281250 # scanned=176997 # found=2 # cleaned=2 C:\System Volume Information\_restore{C2768274-003B-4719-A76C-5E22B1965B5A}\RP760\A0111206.exe Win32/Toolbar.AskSBar application deleted - quarantined G:\aopsfjafjoslsfl\Atalhos não utilizados da área de trabalho\TubeHunterUltra_v2.1.rar probably a variant of Win32/Agent trojan deleted - quarantined # scan_time=11965 log do SmitFraudFix: SmitFraudFix v2.423 Scan done at 13:13:45,82, dom 28/06/2009 Run from C:\Documents and Settings\administrator\Desktop\SmitfraudFix OS: Microsoft Windows XP [versÆo 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» VACFix VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix S!Ri's WS2Fix: LSP not Found. »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files »»»»»»»»»»»»»»»»»»»»»»»» IEDFix IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix Agent.OMZ.Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» 404Fix 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» RK »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{04C3A1DA-9070-4182-B453-44BD34AA1D0F}: DhcpNameServer=192.168.254.254 HKLM\SYSTEM\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{322A6189-5179-47E3-952F-CA74B8365A63}: DhcpNameServer=192.168.254.254 HKLM\SYSTEM\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{B9715597-1E02-47C5-91AE-8A27AB2DF780}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{04C3A1DA-9070-4182-B453-44BD34AA1D0F}: DhcpNameServer=192.168.254.254 HKLM\SYSTEM\CS1\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{322A6189-5179-47E3-952F-CA74B8365A63}: DhcpNameServer=192.168.254.254 HKLM\SYSTEM\CS1\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{B9715597-1E02-47C5-91AE-8A27AB2DF780}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS1\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{04C3A1DA-9070-4182-B453-44BD34AA1D0F}: DhcpNameServer=192.168.254.254 HKLM\SYSTEM\CS2\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{322A6189-5179-47E3-952F-CA74B8365A63}: DhcpNameServer=192.168.254.254 HKLM\SYSTEM\CS2\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{B9715597-1E02-47C5-91AE-8A27AB2DF780}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: DhcpNameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CS2\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer=208.67.220.220,208.67.222.222 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.254.254 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.254.254 HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.254.254 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! "System"="" »»»»»»»»»»»»»»»»»»»»»»»» RK.2 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End e o novo log do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:26:48, on 28/6/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\RocketDock\RocketDock.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\administrator\Desktop\HijackThis.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe" O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: windows_system_32-dll.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) - O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} - O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - (no file) O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - (no file) O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe -- End of file - 7724 bytes Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Junho 29, 2009 :seta: Abra o HijackThis, clique em Do a system scan only, marque a entrada abaixo e clique em Fix checked: O4 - Global Startup: windows_system_32-dll.exe ____________________________________________________________________________ :seta: Vá no menu: Iniciar > Executar e digite: services.msc Tecle Enter. Ache esse Serviço: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o., dê um duplo clique sobre ele com o botão esquerdo do mouse e escolha a opção: Desativado. Clique também em Parar e troque o Tipo de Inicialização para Desativado. Repita este mesmo procedimento acima para desativar também estes outros dois serviços abaixo: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. Bonjour Service - Apple Inc. ____________________________________________________________________________ :seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: Reinicie o PC em entre em Modo Seguro (Fique apertando intermitentemente a tecla F8, ou a tecla F5 em alguns computadores, até que apareça uma tela preta em DOS e escolha a opção: Modo Seguro). * Estando no modo seguro, abra o HijackThis e clique no botão Open the Misc Tools section e depois em Delete an NT service. Digite isto: mDNSResponder Clique em Ok. * clique novamente no botão Open the Misc Tools section e depois em Delete an NT service. Digite isto: Avg7UpdSvc Clique em Ok. * clique novamente no botão Open the Misc Tools section e depois em Delete an NT service. Digite isto: AVGEMS Clique em Ok. Reinicie o computador em Modo Normal. * Vá no menu: Iniciar > Todos os programas > Acessórios > Windows Explorer > Localize esta pasta em destaque abaixo e a exclua: C:\Arquivos de programas\Bonjour ____________________________________________________________________________ :seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: Faça o download do SDFix: http://downloads.andymanchesta.com/RemovalTools/SDFix.exe Salve-o em sua Área de Trabalho (desktop). Dê um duplo clique no SDFix.exe e a Ferramenta será instalada geralmente em C:\SDFix Reinicie o computador em Modo Seguro (pressione a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização) e selecione a opção de Modo Seguro ou Modo de Segurança; Entre na pasta SDFix que foi instalada no seu computador e dê um duplo clique no arquivo RunThis.bat Tecle Y para que a Ferramenta inicie o processo de remoção. Quando tudo terminar, você verá um aviso dizendo para apertar qualquer tecla para continuar. Ao pressionar qualquer tecla, o computador será reiniciado automaticamente. Após reiniciar, a Ferramenta ainda será executada novamente e irá terminar o seu trabalho, e ao surgir "The FixTool has finished", pressione qualquer tecla, uma janela com o Relatório do SDFix irá aparecer. Caso você tenha fechado a janela, uma cópia do Relatório estará na pasta SDFix com o nome Report.txt. Poste este relatório do SDFix na sua próxima resposta juntamente com um novo log do Hijackthis e nos diga como está o seu computador depois de seguir estes procedimentos. Ficamos no aguardo. Depois de usar o SDFix, delete a ferramenta SDFix e a pasta C:\SDFix. Compartilhar este post Link para o post Compartilhar em outros sites
Paulo. 0 Denunciar post Postado Junho 29, 2009 Finalmente deu certo ! :clap: A janelinha não abriu mais ao iniciar o pc! Acho que agora está tudo bem no pc E aí estão os logs: log do SDFix: SDFix: Version 1.240 Run by Administrador on dom 28/06/2009 at 22:58 Microsoft Windows XP [versÆo 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : No Trojan Files Found Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-28 23:12:02 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAI3KP09.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA7ESNZ1.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAI381CL.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAI3C5CP.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAFUWBFD.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAEJ4ROT.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CACPAPTI.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA5007LX.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAOLALDA.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA3M8R7T.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAOP2XPQ.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA63WLMN.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA8L6VOL.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA2FUJI9.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAU7G1E3.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA18G7TP.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAOLELVW.xml 32768 bytes C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA6389A7.xml 32768 bytes scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 18 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"="C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"="C:\\Arquivos de programas\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "C:\\Arquivos de programas\\K-Lite\\eMule\\emule.exe"="C:\\Arquivos de programas\\K-Lite\\eMule\\emule.exe:*:Enabled:eMule" "C:\\Arquivos de programas\\uTorrent\\utorrent.exe"="C:\\Arquivos de programas\\uTorrent\\utorrent.exe:*:Enabled:æTorrent" "C:\\Arquivos de programas\\Mozilla Firefox\\FIREFOX.EXE"="C:\\Arquivos de programas\\Mozilla Firefox\\FIREFOX.EXE:*:Enabled:Firefox" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Arquivos de programas\\Opera\\Opera.exe"="C:\\Arquivos de programas\\Opera\\Opera.exe:*:Enabled:Opera Internet Browser" "C:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe"="C:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe:*:Enabled:VideoAcceleratorService" "G:\\opera.exe"="G:\\opera.exe:*:Enabled:Opera Internet Browser" "C:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAccelerator.exe"="C:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAccelerator.exe:*:Enabled:VideoAccelerator" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"="C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"="C:\\Arquivos de programas\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" Remaining Files : Files with Hidden Attributes : Wed 5 May 1999 95,698 ..SH. --- "C:\COMMAND.COM" Sun 8 Aug 2004 1,676 ..SHR --- "C:\MSDOS.BAK" Sun 8 Aug 2004 53,248 ...H. --- "C:\Arquivos de programas\Acess¢rios\mspcx32.dll" Mon 26 Jan 2009 1,740,632 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\SDUpdate.exe" Mon 26 Jan 2009 5,365,592 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\SpybotSD.exe" Mon 26 Jan 2009 2,144,088 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" Sun 5 Dec 2004 56 ..SHR --- "C:\WINDOWS\system32\4525EC329C.sys" Wed 22 Jun 2005 45,568 A.SHR --- "C:\program files\Replay Converter\cygz.dll" Fri 14 Jan 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.key.bak" Sat 14 Jan 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Wed 5 Dec 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp" Sun 13 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv03.tmp" Sun 6 Mar 2005 20 A..H. --- "C:\Documents and Settings\administrator\Meus documentos\Minhas m£sicas\Backup de Licen‡a\drmv1lic.bak" Fri 14 Jan 2005 4,348 ...H. --- "C:\Documents and Settings\administrator\Meus documentos\Minhas m£sicas\Backup de Licen‡a\drmv1key.bak" Sat 5 Mar 2005 400 A.SH. --- "C:\Documents and Settings\administrator\Meus documentos\Minhas m£sicas\Backup de Licen‡a\drmv2key.bak" Wed 25 Jan 2006 53,318 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\CF_BalletMirror.zip" Wed 25 Jan 2006 43,092 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\CF_MartialArtsMat.zip" Wed 25 Jan 2006 103,683 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_pinkolympicdivingboard.zip" Wed 25 Jan 2006 42,260 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bouncentrim.zip" Wed 25 Jan 2006 44,112 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_grasshandstandv2.zip" Wed 25 Jan 2006 33,334 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_gymtile01.zip" Wed 25 Jan 2006 31,514 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_gymtile02.zip" Wed 25 Jan 2006 57,457 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_gymtile03.zip" Wed 25 Jan 2006 66,159 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_gymtile04.zip" Wed 25 Jan 2006 24,417 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_dancestationmodela1fm.zip" Wed 25 Jan 2006 117,808 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf-slimlineliloblue.zip" Wed 25 Jan 2006 61,265 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_toolroll.ZIP" Wed 25 Jan 2006 34,696 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_magicbroomstick.zip" Wed 25 Jan 2006 320,617 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_forgerseasel.zip" Wed 25 Jan 2006 2,335,303 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_betterbaby.ZIP" Wed 25 Jan 2006 45,249 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_animated_7dsmoviecamera.zip" Wed 25 Jan 2006 715,430 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bedtuckin05.zip" Wed 25 Jan 2006 473,268 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bedtuckin01.zip" Wed 25 Jan 2006 701,382 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bedtuckin03.zip" Wed 25 Jan 2006 476,211 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bedtuckin02.zip" Wed 25 Jan 2006 771,097 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bedtuckin04.zip" Wed 25 Jan 2006 20,215 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cfcrystalball4two.zip" Wed 25 Jan 2006 23,328 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\Stareoutscrn.zip" Finished! e o novo log do HijackThis : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:26:39, on 29/6/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\RocketDock\RocketDock.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\administrator\Desktop\HijackThis.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe" O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) - O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} - O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe -- End of file - 7340 bytes Você recomenda que eu faça ainda algo mais no pc ? E se esse problema voltar ou outro mesmo aparecer eu venho aqui pedir a sua ajuda hehehehe Mas de qualquer jeito muito obrigado Antonio por toda a sua ajuda e também paciência ! hehehehe :joia: Valeu Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Junho 29, 2009 Finalmente deu certo ! A janelinha não abriu mais ao iniciar o pc! Acho que agora está tudo bem no pc :thumbsup: Ficamos felizes que o problema foi resolvido. :seta: Baixe o programa Avenger no link abaixo e extraia o conteúdo para o desktop (área de trabalho): http://swandog46.geekstogo.com/avenger2/download.php *Selecione e copie (Ctrl+C) todo o texto dentro do CODE (caixa branca) abaixo: Files to delete:c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\windows_system_32-dll.exe *Execute o programa Avenger *Clique em [Load Script] > [Paste from Clipboard] *Clique em [Execute] > [OK] *O PC será reiniciado *O relatório será criado em C:\avenger.txt _____________________________________________________________________________ :seta: Instale estes programas e use-os agora e semanalmente para fazer uma limpeza do seu PC e para deixá-lo mais eficiente e otimizado: MV RegClean MV AntiSpy SpywareBlaster _____________________________________________________________________________ :seta: Para evitar que os virus voltem, desative e ative novamente a restauração do sistema. Para isso, vá no menu: Iniciar - Painel de Controle - Sistema - Clique na aba: Restauração do Sistema - Marque a caixinha: Desativar restauração do sistema - Clique no botão: Aplicar e no botão: Ok. Depois disso, volte no mesmo local: Iniciar - Painel de Controle - Sistema - Clique na aba: Restauração do Sistema - Desmarque a caixinha: Desativar restauração do sistema - Clique no botão: Aplicar e no botão: Ok. _____________________________________________________________________________ :seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: Baixe > JavaRa Descompacte-o e dê um duplo-clique no JavaRa.exe. Selecione a língua inglesa (English) ou outro idioma de sua preferência e clique no botão Select. Depois clique em Search For Updates. Selecione a opção Update Using jucheck.exe. Clique então no botão Search. Se o Java estiver atualizado em seu PC, você receberá um aviso de que tem a última versão. Caso contrário, aguarde a nova versão do Java ser baixada e instalada. Feche temporariamente os seus navegadores (Internet Explorer, Firefox, etc). Depois clique no botão Remove Older Versions, confirme clicando no botão Sim e clique em Ok e clique em Ok novamente para que as versões antigas do Java que existirem no PC sejam desinstaladas. _____________________________________________________________________________ :seta: Se o seu Windows for original, baixe e instale o Service Pack 3: http://superdownloads.uol.com.br/download/...s-service-pack/ _____________________________________________________________________________ :seta: Depois de seguir as dicas acima poste um o log do Avenger que estará em C:\avenger.txt juntamente com um novo log do Hijackthis e nos diga como está o seu PC depois disto. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
Paulo. 0 Denunciar post Postado Junho 29, 2009 O meu Windows não é original, mas vou tentar instalar o SP3 quando terminar de baixar, pois a minha conexão é muito lenta E aqui estão os logs: log do Avenger: Logfile of The Avenger Version 2.0, © by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Error: "c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\" is a folder, not a file! Deletion of file "c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\" failed! Status: 0xc00000ba (STATUS_FILE_IS_A_DIRECTORY) --> use "Folders to delete:" instead of "Files to delete:" to delete a directory Error: file "windows_system_32-dll.exe" not found! Deletion of file "windows_system_32-dll.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Completed script processing. ******************* Finished! Terminate. e o novo log do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:32:07, on 29/6/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\RocketDock\RocketDock.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe G:\opera.exe C:\Documents and Settings\administrator\Desktop\programas e coisas que resolveram o Autolt Error\HijackThis.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} - O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe -- End of file - 7172 bytes Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Junho 29, 2009 :!: Você não copiou completamente o texto dentro do CODE e por este motivo o procedimento com o Avenger falhou. Exclua o log do Avenger que está em C:\avenger.txt *Selecione e copie (Ctrl+C) todo o texto dentro do CODE (caixa branca) abaixo: Files to delete:c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\windows_system_32-dll.exe *Execute o programa Avenger *Clique em [Load Script] > [Paste from Clipboard] *Clique em [Execute] > [OK] *O PC será reiniciado *Poste o novo relatório que será criado em C:\avenger.txt na sua próxima resposta. Compartilhar este post Link para o post Compartilhar em outros sites
Paulo. 0 Denunciar post Postado Junho 29, 2009 Eu copiei certo cara Também estranhei quando o log do Avenger disse que não encontrou o windows_system_32-dll.exe Tentei fazer de novo e deu na mesma coisa, windows_system_32-dll.exe not found Mas não foi esta entrada que você pediu para marcar e clicar em Fix checked no HijackThis ? Acho que essa entrada windows_system_32-dll.exe já foi deletada Tenho até o backup aqui! Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Junho 29, 2009 Eu copiei certo caraTambém estranhei quando ele disse que não encontrou o windows_system_32-dll.exe Mas não foi esta entrada que você pediu para marcar e clicar em Fix checked no HijackThis ? Acho que essa entrada windows_system_32-dll.exe já foi deletada Tenho até o backup aqui! :) disse isto porque no seu log do Avenger está constando assim: Error: "c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\" is a folder, not a file! Isto indica que você copiou de C:\ até Inicializar. Mas o certo seria copiar de C:\ até windows_system_32-dll.exe, ficando então assim o texto a ser inserido no Avenger: Files to delete: c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\windows_system_32-dll.exe Compartilhar este post Link para o post Compartilhar em outros sites
Paulo. 0 Denunciar post Postado Junho 29, 2009 De fato esqueci de botar completo Mas acabei de fazer de novo do jeito certo e ainda o Avenger não encontra o windows_system_32-dll.exe Acho que já foi deletada mesmo Logfile of The Avenger Version 2.0, © by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Error: file "c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\windows_system_32-dll.exe" not found! Deletion of file "c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\windows_system_32-dll.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Completed script processing. ******************* Finished! Terminate. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Junho 29, 2009 :) Agora está tudo certo, realmente ele já não existe. :seta: Baixe o programa ToolsCleaner: http://pc-system.fr/TC/ToolsCleaner2.exe Salve-o no Desktop (área de trabalho); Feche programas que estejam abertos e execute a ferramenta. Clique no botão Recherche para iniciar o scan. <-- Aguarde! Terminando, teremos relacionados os itens que serão removidos. Clique no botão Supression para remover os itens encontrados. Clique, à seguir, em Quitter. _____________________________________________________________________________ :seta: Para evitar que os virus voltem, desative e ative novamente a restauração do sistema. Para isso, vá no menu: Iniciar - Painel de Controle - Sistema - Clique na aba: Restauração do Sistema - Marque a caixinha: Desativar restauração do sistema - Clique no botão: Aplicar e no botão: Ok. Depois disso, volte no mesmo local: Iniciar - Painel de Controle - Sistema - Clique na aba: Restauração do Sistema - Desmarque a caixinha: Desativar restauração do sistema - Clique no botão: Aplicar e no botão: Ok. _____________________________________________________________________________ :thumbsup: Foi um prazer ajudar, conte sempre conosco! Compartilhar este post Link para o post Compartilhar em outros sites
Paulo. 0 Denunciar post Postado Junho 30, 2009 Só uma última dúvida, é realmente necessário e recomendável usar o ToolsCleaner ? É que ele remove todos os programas usados neste tópico, mas eu queria guardá-los no caso de precisar no futuro ! Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Junho 30, 2009 Só uma última dúvida, é realmente necessário e recomendável usar o ToolsCleaner ? É que ele remove todos os programas usados neste tópico, mas eu queria guardá-los no caso de precisar no futuro ! Se você quizer deixar os programas usados aí no seu PC você pode deixá-los. Mas há alguns programas como o Combofix, o Avenger e outros que ficarão desatualizados e aí já não serão muito úteis. No caso do Combofix por exemplo o ideal é baixá-lo e utilizá-lo no momento que você precisa (para baixar a versão mais nova dele). Compartilhar este post Link para o post Compartilhar em outros sites