Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Paulo.

[Resolvido!] Mensagem Autolt Error

Recommended Posts

Vem aparecendo aqui sempre que inicia o windows(quando já aparece a área de trabalho) uma janela que diz :

Autolt Error

Line-1:

Error: Variable used without being declared.

 

Mas só aparece ao iniciar mesmo, fora isso não notei nenhuma diferença no desempenho do pc.

O log :

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:51:51, on 24/6/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Winamp\winampa.exe

C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\CyberLink\PowerDVD9\PDVD9Serv.exe

C:\Arquivos de programas\Cyberlink\Shared Files\brs.exe

C:\Arquivos de programas\QuickTime\qttask.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Documents and Settings\administrator\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe

G:\opera.exe

C:\Documents and Settings\administrator\Desktop\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll

O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)

O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp\winampa.exe"

O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [RemoteControl9] "C:\Arquivos de programas\CyberLink\PowerDVD9\PDVD9Serv.exe"

O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD9\Language\Language.exe"

O4 - HKLM\..\Run: [bDRegion] C:\Arquivos de programas\Cyberlink\Shared Files\brs.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\administrator\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: windows_system_32-dll.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -

O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

O20 - AppInit_DLLs: C:\ARQUIV~1\Google\WEBACC~1\FASTSE~1.DLL

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - (no file)

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - (no file)

O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe

O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

 

--

End of file - 9675 bytes

 

Alguém sabe como fazer para essa janela não aparecer mais?

Compartilhar este post


Link para o post
Compartilhar em outros sites

:thumbsup: Olá Paulo!

 

:seta: Está constando em seu PC uma versão bem antiga do antivirus Avg.

 

Para remover completamente o Avg de seu computador você pode usar o desinstalador que o Avg oferece:

 

AVG Remover(32bit) - Use esta opção se o seu sistema for de 32 bit.

AVG Remover(64bit) - Use esta opção se o seu sistema for de 64 bit.

______________________________________________________________________________

 

:seta: Depois disto sugiro que você instale um ótimo antivirus gratuito, como o Avira Antivir Personal 9 Free.

 

Para instalar, configurar e usar corretamente o Avira antivir é só seguir as dicas destes tutoriais:

 

Tutorial do Avira Antivir 9 free (instalação e configuração)

 

Tutorial do Avira Antivir 9 free (como usá-lo corretamente)

______________________________________________________________________________

 

:seta: Depois de instalar e configurar o Avira Antivir seguindo as dicas dos tutoriais acima, atualize-o (faça um update) e reinicie o seu computador e entre pelo Modo de Segurança (apertando a tecla F8 (ou a tecla F5 em alguns computadores) repetidas vezes quando o computador estiver reiniciando e escolhendo a opção Modo Seguro ou Modo de Segurança). Aí quando o computador tiver reiniciado, clique com o botão direito do mouse sobre o símbolo do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Start Antivir > clique na opção Scan system now > e à medida em que forem sendo achados vírus e programas espiões vá enviando eles para a quarentena. Depois de algumas semanas, se o seu computador estiver funcionando normalmente sem estes arquivos que foram para a quarentena, você pode ir na quarentena e excluí-los definitivamente.

 

Quando você tiver removido os virus que o Avira Antivir encontrar, reinicie o computador normalmente. Clique com o botão direito do mouse sobre o ícone do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Start Antivir > clique na opção Reports > dê um duplo clique com o botão esquerdo do mouse sobre o log mais recente e clique no botão Report file > Depois será aberta uma tela com o log, então é só selecionar este Log (Clique no menu: Editar » Selecionar Tudo), depois disso volte novamente no menu: Editar » e clique na opção: Copiar) > Depois disso é só voltar aqui no fórum e postar este log do Avira Antivir juntamente com um novo log do Hijackthis para que eles possam ser analizados.

 

Ficamos no aguardo de sua resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Primeiro, obrigado por responder!

Fiz todas as suas dicas e aí estão os logs

 

o log do Avira AntiVir:

 

 

Avira AntiVir Personal

Report file date: quarta-feira, 24 de junho de 2009 19:49

 

Scanning for 1424788 virus strains and unwanted programs.

 

Licensee : Avira AntiVir Personal - FREE Antivirus

Serial number : 0000149996-ADJIE-0000001

Platform : Windows XP

Windows version : (Service Pack 2) [5.1.2600]

Boot mode : Save mode

Username : Administrador

Computer name : PAULO

 

Version information:

BUILD.DAT : 9.0.0.403 17961 Bytes 3/6/2009 17:05:00

AVSCAN.EXE : 9.0.3.6 466689 Bytes 11/5/2009 13:14:48

AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/2/2009 14:58:26

LUKE.DLL : 9.0.3.2 209665 Bytes 20/2/2009 15:35:50

LUKERES.DLL : 9.0.2.0 12033 Bytes 27/2/2009 14:58:54

ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 16:30:38

ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 24/6/2009 22:19:16

ANTIVIR2.VDF : 7.1.4.133 2048 Bytes 24/6/2009 22:19:18

ANTIVIR3.VDF : 7.1.4.136 15360 Bytes 24/6/2009 22:19:20

Engineversion : 8.2.0.196

AEVDF.DLL : 8.1.1.1 106868 Bytes 30/4/2009 15:52:06

AESCRIPT.DLL : 8.1.2.10 418171 Bytes 24/6/2009 22:21:36

AESCN.DLL : 8.1.2.3 127347 Bytes 14/5/2009 15:02:02

AERDL.DLL : 8.1.1.3 438645 Bytes 29/10/2008 22:24:42

AEPACK.DLL : 8.1.3.18 401783 Bytes 27/5/2009 20:07:22

AEOFFICE.DLL : 8.1.0.38 196987 Bytes 24/6/2009 22:21:20

AEHEUR.DLL : 8.1.0.134 1802616 Bytes 24/6/2009 22:21:14

AEHELP.DLL : 8.1.3.6 205174 Bytes 24/6/2009 22:19:46

AEGEN.DLL : 8.1.1.46 348533 Bytes 24/6/2009 22:19:40

AEEMU.DLL : 8.1.0.9 393588 Bytes 9/10/2008 18:32:40

AECORE.DLL : 8.1.6.12 180599 Bytes 27/5/2009 20:07:22

AEBB.DLL : 8.1.0.3 53618 Bytes 9/10/2008 18:32:40

AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 12:48:00

AVPREF.DLL : 9.0.0.1 43777 Bytes 5/12/2008 14:32:16

AVREP.DLL : 8.0.0.3 155905 Bytes 20/1/2009 18:34:30

AVREG.DLL : 9.0.0.0 36609 Bytes 5/12/2008 14:32:10

AVARKT.DLL : 9.0.0.3 292609 Bytes 24/3/2009 19:05:42

AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/1/2009 14:37:10

SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/1/2009 19:03:50

SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 12:21:34

NETNT.DLL : 9.0.0.0 11521 Bytes 5/12/2008 14:32:12

RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/5/2009 19:40:00

RCTEXT.DLL : 9.0.37.0 86785 Bytes 17/4/2009 14:19:50

 

Configuration settings for the scan:

Jobname.............................: Complete system scan

Configuration file..................: c:\arquivos de programas\avira\antivir desktop\sysscan.avp

Logging.............................: low

Primary action......................: repair

Secondary action....................: quarantine

Scan master boot sector.............: on

Scan boot sector....................: on

Boot sectors........................: C:, G:,

Process scan........................: on

Scan registry.......................: on

Search for rootkits.................: on

Integrity checking of system files..: off

Scan all files......................: All files

Scan archives.......................: on

Recursion depth.....................: 20

Smart extensions....................: on

Macro heuristic.....................: on

File heuristic......................: medium

Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+SPR,

 

Start of the scan: quarta-feira, 24 de junho de 2009 19:49

 

Starting search for hidden objects.

The driver could not be initialized.

 

The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'Explorer.EXE' - '1' Module(s) have been scanned

Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned

Scan process 'unsecapp.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'AAWService.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

14 processes with 14 modules were scanned

 

Starting master boot sector scan:

Master boot sector HD0

[iNFO] No virus was found!

Master boot sector HD1

[iNFO] No virus was found!

 

Start scanning boot sectors:

Boot sector 'C:\'

[iNFO] No virus was found!

Boot sector 'G:\'

[iNFO] No virus was found!

 

Starting to scan executable files (registry).

The registry was scanned ( '48' files ).

 

 

Starting the file scan:

 

Begin scan in 'C:\'

C:\pagefile.sys

[WARNING] The file could not be opened!

[NOTE] This file is a Windows system file.

[NOTE] This file cannot be opened for scanning.

C:\System Volume Information\_restore{C2768274-003B-4719-A76C-5E22B1965B5A}\RP761\A0111269.exe

[DETECTION] Is the TR/Keygen.BM Trojan

[NOTE] The file was moved to '4a73bfe2.qua'!

Begin scan in 'G:\' <HD_320GB>

G:\aopsfjafjoslsfl\Jogos\gameboy(color e advance)\gameboy(color e advance),\TGB_Dual_7.zip

[0] Archive type: ZIP

--> devices/tbr_dll.dll

[DETECTION] Is the TR/Gologger.D.3 Trojan

[NOTE] The file was moved to '4a84c39b.qua'!

G:\aopsfjafjoslsfl\programas\Nero 9.4.13.2 Ultra Edition 2009 + Working Keygen [h33t].rar

[0] Archive type: RAR

--> Keygen.exe

[DETECTION] Contains a recognition pattern of the (harmful) BDS/Bifrose.bbld.20 back-door program

[NOTE] The file was moved to '4ab4c58f.qua'!

 

 

End of the scan: quarta-feira, 24 de junho de 2009 21:36

Used time: 1:46:18 Hour(s)

 

The scan has been done completely.

 

12421 Scanned directories

411098 Files were scanned

3 Viruses and/or unwanted programs were found

0 Files were classified as suspicious

0 files were deleted

0 Viruses and unwanted programs were repaired

3 Files were moved to quarantine

0 Files were renamed

1 Files cannot be scanned

411094 Files not concerned

8261 Archives were scanned

1 Warnings

4 Notes

 

 

e o novo log do HijackThis:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:01:45, on 24/6/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Winamp\winampa.exe

C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\CyberLink\PowerDVD9\PDVD9Serv.exe

C:\Arquivos de programas\Cyberlink\Shared Files\brs.exe

C:\Arquivos de programas\QuickTime\qttask.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Documents and Settings\administrator\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe

C:\WINDOWS\system32\notepad.exe

G:\opera.exe

C:\Documents and Settings\administrator\Desktop\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\ARQUIV~1\SPEEDB~1\vaproxy.pac

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll

O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)

O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp\winampa.exe"

O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [RemoteControl9] "C:\Arquivos de programas\CyberLink\PowerDVD9\PDVD9Serv.exe"

O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD9\Language\Language.exe"

O4 - HKLM\..\Run: [bDRegion] C:\Arquivos de programas\Cyberlink\Shared Files\brs.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\administrator\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: windows_system_32-dll.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -

O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

O20 - AppInit_DLLs: C:\ARQUIV~1\Google\WEBACC~1\FASTSE~1.DLL

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - (no file)

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - (no file)

O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe

O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

 

--

End of file - 10367 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

:thumbsup: Três problemas foram removidos pelo Avira.

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked:

 

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

 

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

 

O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)

________________________________________________________________________________

 

:seta: Há programas desnecessários iniciando junto com o Windows, o que torna o seu PC mais lento. Para corrigir isto, siga as dicas deste tutorial:

 

Escolhendo Programas que Iniciam com o PC

 

De preferência deixe apenas os programas de segurança (anti-vírus/anti-spywares/firewall) iniciarem junto com o Windows.

 

Use também o programa Ccleaner, indicado neste tutorial acima, para fazer uma limpeza e otimização do PC agora e de tempos em tempos.

 

Para fazer esta limpeza com o Ccleaner faça o seguinte: Abra o Ccleaner > clique em Executar Limpeza > Clique em Ok.

 

Após isto, clique em Registro > Procurar erros > Corrigir erros selecionados

________________________________________________________________________________

 

:seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

Baixe o ComboFix em:

ComboFix

 

1) Desabilite o seu anti-vírus temporariamente;

 

2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos);

 

3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Clique em “SIM” para continuar.

 

4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console antes de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura.

 

Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente.

 

Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA.

 

Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADO COM SUCESSO”.

 

Clique sobre “SIM” para continuar a varredura.

 

5) O ComboFix iniciará o AUTOSCAN (aguarde).

 

ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco).

 

Ao término do processo a máquina será reiniciada para a emissão do relatório.

 

6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log dele estará em C:\ComboFix.txt.

 

7) Reabilite o seu anti-vírus;

 

OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix.

Em último caso, se não for possível executar o Combofix no Modo Normal do Windows, tente utilizar o ComboFix em MODO SEGURO (reiniciando o computador e pressionando a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização e escolha a opção Modo Seguro na tela que se apresenta) e repita o procedimento;

 

OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB.

* Se por algum motivo você precisar parar ou sair do ComboFix, tecle "N".

* Se perder a conexão com a internet, reinicie o computador. Caso o problema persista, abra Conexões de Rede no Painel de Controle, clique com o botão direito do mouse sobre a sua conexão com a internet e em "Reparar";

 

Poste o log do Combofix que estará em C:\ComboFix.txt juntamente com um novo log do Hijackthis em sua próxima resposta e nos diga como está o seu PC depois disto.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Antonio, fiz todas as suas instruções, mas infelizmente aquela janelinha continua aparecendo (http://img195.imageshack.us/img195/3366/imagemxaz.jpg) ao iniciar o computador(só aparece mesmo nessa ocasião) :unsure:

Acho até que nem é um problema de malware!

E eu não consigo desistalar esse AVG, mesmo usando o AVG Remover ! e na aba Ferramentas do CCleaner > Desinstalar programas ele também não aparece!

Então para usar o Combofix só consegui desativar mesmo o Avira AntiVir ! Mas mesmo assim consegui usar o ComboFix e aqui estão os logs:

 

log do ComboFix:

 

ComboFix 09-06-26.02 - administrator 26/06/2009 16:55.1 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.447.27 [GMT -3:00]

Executando de: c:\documents and settings\administrator\Desktop\ComboFix.exe

AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

AV: AVG 7.5.441 *On-access scanning enabled* (Updated) {41564737-3200-1071-989B-0000E87B4FB1}

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\new.exe

c:\windows\patch.exe

c:\windows\system32\Process.exe

c:\windows\system32\SrchSTS.exe

c:\windows\system32\tmp.reg

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2009-05-26 to 2009-06-26 ))))))))))))))))))))))))))))

.

 

2009-06-26 16:22 . 2009-06-26 16:22 -------- d-----w- c:\arquivos de programas\Perfect Optimizer

2009-06-26 04:04 . 2009-06-26 04:04 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\AVS4YOU

2009-06-26 03:54 . 2009-06-26 03:54 -------- d-----w- c:\arquivos de programas\Arquivos comuns\AVSMedia

2009-06-26 03:54 . 2007-09-27 17:22 261632 ----a-w- c:\windows\system32\mcdvd_32.dll

2009-06-26 03:54 . 2003-05-22 02:50 1700352 ----a-w- c:\windows\system32\GdiPlus.dll

2009-06-26 03:54 . 2002-01-05 18:48 974848 ----a-w- c:\windows\system32\mfc70.dll

2009-06-26 03:54 . 2009-06-26 03:54 -------- d-----w- c:\arquivos de programas\AVS4YOU

2009-06-26 02:08 . 2009-06-26 02:08 -------- d-----w- C:\rsit

2009-06-25 21:12 . 2009-06-25 21:12 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\NeroDigital

2009-06-24 23:47 . 2009-06-24 23:47 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Winamp

2009-06-24 22:48 . 2009-06-24 22:48 -------- d-sh--w- c:\documents and settings\Administrador\IETldCache

2009-06-24 21:51 . 2009-03-30 13:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys

2009-06-24 21:51 . 2009-02-13 15:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys

2009-06-24 21:51 . 2009-02-13 15:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys

2009-06-24 21:51 . 2009-06-24 21:51 -------- d-----w- c:\arquivos de programas\Avira

2009-06-24 06:04 . 2009-06-24 06:04 -------- d-----w- c:\arquivos de programas\MSXML 4.0

2009-06-24 02:30 . 2009-03-24 19:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2009-06-24 02:26 . 2009-06-24 02:26 -------- d-----r- c:\documents and settings\LocalService\Meus documentos

2009-06-24 02:00 . 2009-06-24 01:58 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys

2009-06-24 01:59 . 2009-06-24 01:59 314200 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Lavasoft\Ad-Aware\update\threatwork.exe

2009-06-24 01:57 . 2009-06-24 01:57 518488 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Lavasoft\Ad-Aware\update\AAWTray.exe

2009-06-24 01:57 . 2009-06-24 01:57 1003344 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Lavasoft\Ad-Aware\update\AAWService.exe

2009-06-24 01:48 . 2009-01-18 21:43 2892112 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe

2009-06-24 01:48 . 2009-06-24 01:48 -------- d--h--w- c:\documents and settings\All Users\Dados de aplicativos\{83C91755-2546-441D-AC40-9A6B4B860800}

2009-06-24 01:28 . 2009-06-24 01:28 -------- d-----w- c:\arquivos de programas\VS Revo Group

2009-06-24 01:27 . 2009-06-24 01:27 -------- d-----w- c:\arquivos de programas\RenomearTudo

2009-06-23 19:36 . 2009-06-23 19:36 -------- d-----w- c:\arquivos de programas\FormatFactory

2009-06-23 18:06 . 2009-06-23 18:07 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\InterVideo

2009-06-23 17:52 . 2009-06-23 17:52 -------- d-----w- c:\arquivos de programas\QuickTime

2009-06-23 17:51 . 2009-06-23 17:51 -------- d-----w- c:\arquivos de programas\Apple Software Update

2009-06-23 17:47 . 2009-06-23 17:47 -------- d-----w- c:\arquivos de programas\InterVideo Information Service

2009-06-23 17:47 . 2009-06-23 17:47 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Ulead

2009-06-23 17:45 . 2009-06-23 17:45 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\InstallShield

2009-06-23 06:07 . 2009-06-23 06:07 -------- d-----w- c:\arquivos de programas\RocketDock

2009-06-23 02:52 . 2009-06-23 02:52 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\Nero

2009-06-23 02:25 . 2009-06-23 02:25 -------- d-----w- c:\arquivos de programas\Windows Sidebar

2009-06-23 01:50 . 2009-06-23 01:50 -------- d-----w- c:\arquivos de programas\Nero

2009-06-23 01:49 . 2009-06-23 01:49 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Nero

2009-06-23 01:49 . 2009-06-23 01:49 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Nero

2009-06-23 00:56 . 2009-06-23 00:56 -------- d-----w- c:\arquivos de programas\uTorrent Ultra Accelerator

2009-06-22 21:38 . 2009-06-22 21:38 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\CyberLink

2009-06-22 21:34 . 2009-06-22 21:34 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\CyberLink

2009-06-22 21:29 . 2003-05-21 15:50 24576 ----a-w- c:\windows\system32\msxml3a.dll

2009-06-22 21:28 . 2009-06-22 21:28 -------- d-----w- c:\arquivos de programas\Arquivos comuns\CyberLink

2009-06-22 20:42 . 2009-06-25 18:31 53319 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Temp\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe

2009-06-22 20:42 . 2009-06-22 20:42 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Temp

2009-06-22 17:01 . 2009-06-22 17:01 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\COWON

2009-06-22 16:59 . 2009-06-22 16:59 -------- d-----w- c:\arquivos de programas\Arquivos comuns\COWON

2009-06-22 16:59 . 2009-06-22 16:59 -------- d-----w- c:\arquivos de programas\JetAudio

2009-06-22 16:58 . 2009-06-22 16:58 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\InstallShield

2009-06-22 15:52 . 2009-06-22 15:52 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\dvdcss

2009-06-22 15:51 . 2009-06-22 15:51 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\vlc

2009-06-22 15:50 . 2009-06-22 15:50 -------- d-----w- c:\arquivos de programas\VideoLAN

2009-06-20 00:23 . 2009-06-20 00:23 -------- d-----w- c:\arquivos de programas\Lavalys

2009-06-11 19:24 . 2009-04-30 21:14 12800 ------w- c:\windows\system32\dllcache\xpshims.dll

2009-06-11 19:24 . 2009-04-30 21:14 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll

2009-06-10 00:12 . 2009-06-10 00:12 -------- d-----w- c:\arquivos de programas\Palavras-Cruzadas 8.0

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-06-25 18:19 . 2006-01-07 00:05 2728 ----a-w- c:\windows\system32\d3d9caps.dat

2009-06-24 01:59 . 2009-06-24 01:58 25440 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Lavasoft\Ad-Aware\update\savapibridge.dll

2009-06-22 12:54 . 2001-10-28 18:07 61400 ----a-w- c:\windows\system32\perfc016.dat

2009-06-22 12:54 . 2001-10-28 18:07 413126 ----a-w- c:\windows\system32\perfh016.dat

2009-05-15 11:02 . 2009-05-15 11:02 2373416 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Nero\Nero\DrWeb\DrWeb32.dll

2009-05-15 10:50 . 2009-05-15 10:50 2373416 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Nero\Nero 9\DrWeb\DrWeb32.dll

2009-05-13 05:03 . 2004-08-04 06:45 915456 ----a-w- c:\windows\system32\wininet.dll

2009-05-08 19:46 . 2009-05-08 19:46 -------- d-----w- c:\arquivos de programas\Arquivos comuns\xing shared

2009-05-08 19:45 . 2003-03-18 23:14 499712 ----a-w- c:\windows\system32\msvcp71.dll

2009-05-08 19:24 . 2009-05-08 19:24 -------- d-----w- c:\documents and settings\administrator\Dados de aplicativos\Winamp

2009-05-07 15:43 . 2004-08-04 06:45 345600 ----a-w- c:\windows\system32\localspl.dll

2009-04-19 20:10 . 2004-08-04 06:38 1846784 ----a-w- c:\windows\system32\win32k.sys

2009-04-15 15:17 . 2004-08-04 06:45 584192 ----a-w- c:\windows\system32\rpcrt4.dll

2004-07-22 13:51 . 2004-07-22 13:51 3432656 ----a-w- c:\arquivos de programas\ManagedDX.CAB

2004-07-20 01:58 . 2004-07-20 01:58 1156363 ----a-w- c:\arquivos de programas\BDANT.cab

2004-07-20 01:53 . 2004-07-20 01:53 976020 ----a-w- c:\arquivos de programas\BDAXP.cab

2004-07-09 17:17 . 2004-07-09 17:17 13265040 ----a-w- c:\arquivos de programas\dxnt.cab

2004-07-09 12:13 . 2004-07-09 12:13 15493481 ----a-w- c:\arquivos de programas\DirectX.cab

2004-07-09 12:13 . 2004-07-09 12:13 703080 ----a-w- c:\arquivos de programas\BDA.cab

2004-07-09 07:08 . 2004-07-09 07:08 472576 ----a-w- c:\arquivos de programas\dxsetup.exe

2004-07-09 07:08 . 2004-07-09 07:08 2242560 ----a-w- c:\arquivos de programas\dsetup32.dll

2004-07-09 06:03 . 2004-07-09 06:03 62976 ----a-w- c:\arquivos de programas\DSETUP.dll

2009-04-18 22:42 . 2008-01-19 01:55 67688 ----a-w- c:\arquivos de programas\mozilla firefox\components\jar50.dll

2009-04-18 22:42 . 2008-01-19 01:55 54368 ----a-w- c:\arquivos de programas\mozilla firefox\components\jsd3250.dll

2009-04-18 22:42 . 2008-01-19 01:55 34944 ----a-w- c:\arquivos de programas\mozilla firefox\components\myspell.dll

2009-04-18 22:42 . 2008-01-19 01:55 46712 ----a-w- c:\arquivos de programas\mozilla firefox\components\spellchk.dll

2009-04-18 22:42 . 2008-01-19 01:55 172136 ----a-w- c:\arquivos de programas\mozilla firefox\components\xpinstal.dll

2004-12-06 01:55 . 2004-12-06 01:55 56 --sh--r- c:\windows\system32\4525EC329C.sys

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

"SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

"RocketDock"="c:\arquivos de programas\RocketDock\RocketDock.exe" [2007-09-02 495616]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpeedBitVideoAccelerator"="c:\arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe" [2008-06-07 2705008]

"Ad-Watch"="c:\arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-24 518488]

"avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

"DWQueuedReporting"="c:\arquiv~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 36040]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

windows_system_32-dll.exe [2009-6-11 337495]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0\0lsdelete

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

@="Service"

 

[HKLM\~\startupfolder\C:^Documents and Settings^administrator^Menu Iniciar^Programas^Inicializar^BHODemon 2.0.lnk]

backup=c:\windows\pss\BHODemon 2.0.lnkStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk]

backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Atualizador - Puxa Rápido

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeskAd Service

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostStartTrayApp

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TM Outbreak Agent

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\K-Lite\\eMule\\emule.exe"=

"c:\\Arquivos de programas\\uTorrent\\utorrent.exe"=

"c:\\Arquivos de programas\\Mozilla Firefox\\FIREFOX.EXE"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Opera\\Opera.exe"=

"c:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe"=

"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=

"g:\\opera.exe"=

"c:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAccelerator.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"4662:TCP"= 4662:TCP:porta legal

"4672:UDP"= 4672:UDP:porta legal 2

 

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [23/6/2009 23:00 64160]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [24/6/2009 18:51 108289]

R2 sbbotdi;sbbotdi;c:\arquiv~1\SPEEDB~1\sbbotdi.sys [10/3/2007 11:02 35584]

R2 VideoAcceleratorService;VideoAcceleratorService;c:\arquiv~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm --> c:\arquiv~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]

S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [21/9/2006 12:24 450400]

S3 FXDRV;FXDRV;\??\d:\fxdrv.sys --> d:\Fxdrv.sys [?]

 

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-06-26 c:\windows\Tasks\User_Feed_Synchronization-{E85D7ADC-D05F-4F20-B134-EDF5136335A4}.job

- c:\windows\system32\msfeedssync.exe [2006-10-17 07:31]

 

2009-06-23 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2006-08-29 17:21]

 

2009-06-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\arquivos de programas\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 01:58]

.

- - - - ORFÃOS REMOVIDOS - - - -

 

Notify-WgaLogon - (no file)

SafeBoot-Lavasoft Ad-Aware Service

MSConfigStartUp-pccguide - (no file)

MSConfigStartUp-PCClient - (no file)

 

 

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = iexplore

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Backward &Links

IE: Cac&hed Snapshot of Page

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~1\Office10\EXCEL.EXE/3000

IE: shorten url - http://www.cjb.net/menuext.html

IE: Si&milar Pages

TCP: {01EBD1BD-D540-44FD-9A92-A33BB92BDC7F} = 208.67.220.220,208.67.222.222

TCP: {0416794C-9083-4544-8163-0CFA90D1BAAB} = 208.67.220.220,208.67.222.222

TCP: {04F3740A-F11D-4900-B82A-564CCB9D4053} = 208.67.220.220,208.67.222.222

TCP: {3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE} = 208.67.220.220,208.67.222.222

TCP: {7862CE84-3DED-42EE-9750-CDA60936645C} = 208.67.220.220,208.67.222.222

TCP: {A0CB817D-AD60-4906-ACEC-72A8597BEA66} = 208.67.220.220,208.67.222.222

TCP: {BA9F9753-48FF-4E38-A888-5DA40DBCFEA4} = 208.67.220.220,208.67.222.222

TCP: {BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F} = 208.67.220.220,208.67.222.222

TCP: {DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0} = 208.67.220.220,208.67.222.222

TCP: {E51DCA47-FE65-4BF2-9868-5777F46E8306} = 208.67.220.220,208.67.222.222

DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE}

FF - ProfilePath - c:\documents and settings\administrator\Dados de aplicativos\Mozilla\Firefox\Profiles\g1igenwf.Novo perfil criado dia 09.07.2008\

FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q=

FF - prefs.js: browser.search.selectedEngine - BS_Player Customized Web Search

FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1750559&SearchSource=13

FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&q=

FF - component: c:\arquivos de programas\Google\Web Accelerator\firefox\components\GoogleWebAccFirefox.dll

FF - component: c:\arquivos de programas\Mozilla Firefox\components\xpinstal.dll

FF - component: c:\documents and settings\administrator\Dados de aplicativos\Mozilla\Firefox\Profiles\g1igenwf.Novo perfil criado dia 09.07.2008\extensions\{31513E58-F253-47ad-86DB-D5F21E905429}\components\mintray-9178506d-2005072516-trunk.dll

FF - component: c:\documents and settings\administrator\Dados de aplicativos\Mozilla\Firefox\Profiles\g1igenwf.Novo perfil criado dia 09.07.2008\extensions\piclens@cooliris.com\components\piclensstub.dll

FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-06-26 17:04

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_USERS\S-1-5-21-602162358-1060284298-1202660629-1003\Software\G*e*n*i*e*"!\FM Genie Scout]

"LoadLangDB"=dword:00000001

"CompressHistoryPoints"=dword:00000000

"HighlightedAttributes"=dword:00000000

"HighQualityGUI"=dword:00000000

"ShowHistory"=dword:00000001

"WindowState"=dword:00000002

"Currency"=dword:00000056

"WindowHeight"=dword:00000250

"WindowWidth"=dword:0000032c

"WindowLeft"=dword:0000006a

"WindowTop"=dword:00000058

"AdvancedGeneration"=dword:00000001

 

[HKEY_USERS\S-1-5-21-602162358-1060284298-1202660629-1003\Software\G*e*n*i*e*"!\FM Genie Scout\Columns\Players]

"Position0"=dword:00000000

"Visible0"=dword:00000001

"Width0"=dword:0000007d

"Position1"=dword:00000001

"Visible1"=dword:00000001

"Width1"=dword:00000064

"Position2"=dword:00000002

"Visible2"=dword:00000001

"Width2"=dword:00000064

"Position3"=dword:00000003

"Visible3"=dword:00000001

"Width3"=dword:00000037

"Position4"=dword:00000005

"Visible4"=dword:00000001

"Width4"=dword:00000028

"Position5"=dword:00000006

"Visible5"=dword:00000001

"Width5"=dword:00000028

"Position6"=dword:00000004

"Visible6"=dword:00000001

"Width6"=dword:00000028

"Position7"=dword:00000008

"Visible7"=dword:00000001

"Width7"=dword:0000004b

"Position8"=dword:00000009

"Visible8"=dword:00000001

"Width8"=dword:0000004b

"Position9"=dword:0000000a

"Visible9"=dword:00000001

"Width9"=dword:00000050

"Position10"=dword:0000000c

"Visible10"=dword:00000000

"Width10"=dword:00000050

"Position11"=dword:0000000d

"Visible11"=dword:00000001

"Width11"=dword:0000004b

"Position12"=dword:0000000e

"Visible12"=dword:00000000

"Width12"=dword:0000002d

"Position13"=dword:0000000f

"Visible13"=dword:00000000

"Width13"=dword:0000003c

"Position14"=dword:00000010

"Visible14"=dword:00000000

"Width14"=dword:0000004b

"Position15"=dword:00000011

"Visible15"=dword:00000000

"Width15"=dword:00000064

"Position16"=dword:00000012

"Visible16"=dword:00000000

"Width16"=dword:00000064

"Position17"=dword:00000013

"Visible17"=dword:00000000

"Width17"=dword:0000004b

"Position18"=dword:00000014

"Visible18"=dword:00000000

"Width18"=dword:00000064

"Position19"=dword:00000015

"Visible19"=dword:00000000

"Width19"=dword:0000003c

"Position20"=dword:00000016

"Visible20"=dword:00000000

"Width20"=dword:0000004b

"Position21"=dword:00000017

"Visible21"=dword:00000000

"Width21"=dword:00000050

"Position22"=dword:00000018

"Visible22"=dword:00000000

"Width22"=dword:00000073

"Position23"=dword:00000019

"Visible23"=dword:00000000

"Width23"=dword:00000050

"Position24"=dword:0000001a

"Visible24"=dword:00000000

"Width24"=dword:0000005a

"Position25"=dword:0000001b

"Visible25"=dword:00000000

"Width25"=dword:0000006e

"Position26"=dword:0000001c

"Visible26"=dword:00000000

"Width26"=dword:00000064

"Position27"=dword:0000001d

"Visible27"=dword:00000000

"Width27"=dword:00000087

"Position28"=dword:0000001e

"Visible28"=dword:00000000

"Width28"=dword:00000064

"Position29"=dword:0000001f

"Visible29"=dword:00000000

"Width29"=dword:00000064

"Position30"=dword:00000020

"Visible30"=dword:00000000

"Width30"=dword:00000046

"Position31"=dword:00000021

"Visible31"=dword:00000000

"Width31"=dword:0000004b

"Position32"=dword:00000022

"Visible32"=dword:00000000

"Width32"=dword:00000046

"Position33"=dword:00000023

"Visible33"=dword:00000000

"Width33"=dword:0000004b

"Position34"=dword:00000024

"Visible34"=dword:00000000

"Width34"=dword:0000003c

"Position35"=dword:00000026

"Visible35"=dword:00000000

"Width35"=dword:00000064

"Position36"=dword:0000002a

"Visible36"=dword:00000000

"Width36"=dword:00000073

"Position37"=dword:0000002c

"Visible37"=dword:00000000

"Width37"=dword:0000005f

"Position38"=dword:0000002f

"Visible38"=dword:00000000

"Width38"=dword:00000091

"Position39"=dword:00000031

"Visible39"=dword:00000000

"Width39"=dword:0000003c

"Position40"=dword:00000028

"Visible40"=dword:00000000

"Width40"=dword:0000005a

"Position41"=dword:00000032

"Visible41"=dword:00000000

"Width41"=dword:00000041

"Position42"=dword:00000025

"Visible42"=dword:00000000

"Width42"=dword:00000050

"Position43"=dword:00000027

"Visible43"=dword:00000000

"Width43"=dword:00000055

"Position44"=dword:00000029

"Visible44"=dword:00000000

"Width44"=dword:0000005f

"Position45"=dword:00000033

"Visible45"=dword:00000000

"Width45"=dword:00000050

"Position46"=dword:00000034

"Visible46"=dword:00000000

"Width46"=dword:0000004b

"Position47"=dword:00000035

"Visible47"=dword:00000000

"Width47"=dword:0000004b

"Position48"=dword:00000036

"Visible48"=dword:00000000

"Width48"=dword:00000046

"Position49"=dword:00000037

"Visible49"=dword:00000000

"Width49"=dword:00000032

"Position50"=dword:00000038

"Visible50"=dword:00000000

"Width50"=dword:0000003c

"Position51"=dword:00000039

"Visible51"=dword:00000000

"Width51"=dword:0000004b

"Position52"=dword:0000003a

"Visible52"=dword:00000000

"Width52"=dword:0000003c

"Position53"=dword:0000003b

"Visible53"=dword:00000000

"Width53"=dword:00000037

"Position54"=dword:0000003c

"Visible54"=dword:00000000

"Width54"=dword:00000069

"Position55"=dword:0000003d

"Visible55"=dword:00000000

"Width55"=dword:0000005a

"Position56"=dword:00000040

"Visible56"=dword:00000000

"Width56"=dword:0000004b

"Position57"=dword:00000041

"Visible57"=dword:00000000

"Width57"=dword:0000004b

"Position58"=dword:00000042

"Visible58"=dword:00000000

"Width58"=dword:00000037

"Position59"=dword:00000043

"Visible59"=dword:00000000

"Width59"=dword:0000003c

"Position60"=dword:00000044

"Visible60"=dword:00000000

"Width60"=dword:0000003c

"Position61"=dword:00000045

"Visible61"=dword:00000000

"Width61"=dword:00000041

"Position62"=dword:00000046

"Visible62"=dword:00000000

"Width62"=dword:00000055

"Position63"=dword:00000047

"Visible63"=dword:00000000

"Width63"=dword:0000003c

"Position64"=dword:00000048

"Visible64"=dword:00000000

"Width64"=dword:0000003c

"Position65"=dword:00000049

"Visible65"=dword:00000000

"Width65"=dword:0000004b

"Position66"=dword:0000004a

"Visible66"=dword:00000000

"Width66"=dword:0000003c

"Position67"=dword:0000004b

"Visible67"=dword:00000000

"Width67"=dword:00000046

"Position68"=dword:0000004c

"Visible68"=dword:00000000

"Width68"=dword:00000028

"Position69"=dword:0000004d

"Visible69"=dword:00000000

"Width69"=dword:00000041

"Position70"=dword:0000004e

"Visible70"=dword:00000000

"Width70"=dword:0000003c

"Position71"=dword:0000004f

"Visible71"=dword:00000000

"Width71"=dword:00000069

"Position72"=dword:00000050

"Visible72"=dword:00000000

"Width72"=dword:00000041

"Position73"=dword:00000051

"Visible73"=dword:00000000

"Width73"=dword:0000005f

"Position74"=dword:00000052

"Visible74"=dword:00000000

"Width74"=dword:0000003c

"Position75"=dword:00000053

"Visible75"=dword:00000000

"Width75"=dword:00000037

"Position76"=dword:00000054

"Visible76"=dword:00000000

"Width76"=dword:0000004b

"Position77"=dword:00000055

"Visible77"=dword:00000000

"Width77"=dword:00000050

"Position78"=dword:00000056

"Visible78"=dword:00000000

"Width78"=dword:00000037

"Position79"=dword:00000057

"Visible79"=dword:00000000

"Width79"=dword:00000037

"Position80"=dword:00000058

"Visible80"=dword:00000000

"Width80"=dword:0000005a

"Position81"=dword:00000059

"Visible81"=dword:00000000

"Width81"=dword:0000004b

"Position82"=dword:0000005a

"Visible82"=dword:00000000

"Width82"=dword:00000055

"Position83"=dword:0000005b

"Visible83"=dword:00000000

"Width83"=dword:0000002d

"Position84"=dword:0000005c

"Visible84"=dword:00000000

"Width84"=dword:00000037

"Position85"=dword:0000005d

"Visible85"=dword:00000000

"Width85"=dword:0000003c

"Position86"=dword:0000005e

"Visible86"=dword:00000000

"Width86"=dword:00000046

"Position87"=dword:0000005f

"Visible87"=dword:00000000

"Width87"=dword:0000003c

"Position88"=dword:00000060

"Visible88"=dword:00000000

"Width88"=dword:0000005a

"Position89"=dword:00000061

"Visible89"=dword:00000000

"Width89"=dword:0000003c

"Position90"=dword:00000062

"Visible90"=dword:00000000

"Width90"=dword:00000050

"Position91"=dword:00000063

"Visible91"=dword:00000000

"Width91"=dword:00000046

"Position92"=dword:00000064

"Visible92"=dword:00000000

"Width92"=dword:0000005a

"Position93"=dword:00000065

"Visible93"=dword:00000000

"Width93"=dword:00000037

"Position94"=dword:00000066

"Visible94"=dword:00000000

"Width94"=dword:0000003c

"Position95"=dword:00000067

"Visible95"=dword:00000000

"Width95"=dword:0000003c

"Position96"=dword:00000068

"Visible96"=dword:00000000

"Width96"=dword:00000046

"Position97"=dword:00000069

"Visible97"=dword:00000000

"Width97"=dword:00000046

"Position98"=dword:0000006a

"Visible98"=dword:00000000

"Width98"=dword:00000055

"Position99"=dword:0000006b

"Visible99"=dword:00000000

"Width99"=dword:00000073

"Position100"=dword:0000003e

"Visible100"=dword:00000000

"Width100"=dword:00000041

"Position101"=dword:0000006c

"Visible101"=dword:00000000

"Width101"=dword:0000003c

"Position102"=dword:0000006d

"Visible102"=dword:00000000

"Width102"=dword:0000003c

"Position103"=dword:0000006e

"Visible103"=dword:00000000

"Width103"=dword:00000046

"Position104"=dword:0000006f

"Visible104"=dword:00000000

"Width104"=dword:0000003c

"Position105"=dword:00000070

"Visible105"=dword:00000000

"Width105"=dword:00000041

"Position106"=dword:0000000b

"Visible106"=dword:00000001

"Width106"=dword:0000005a

"Position107"=dword:00000007

"Visible107"=dword:00000001

"Width107"=dword:00000028

"Position108"=dword:0000003f

"Visible108"=dword:00000000

"Width108"=dword:00000050

"Position109"=dword:0000002b

"Visible109"=dword:00000000

"Width109"=dword:00000050

"Position110"=dword:0000002d

"Visible110"=dword:00000000

"Width110"=dword:00000055

"Position111"=dword:0000002e

"Visible111"=dword:00000000

"Width111"=dword:00000082

"Position112"=dword:00000030

"Visible112"=dword:00000000

"Width112"=dword:00000087

"Position113"=dword:00000071

"Visible113"=dword:00000000

"Width113"=dword:00000050

"Position114"=dword:00000072

"Visible114"=dword:00000000

"Width114"=dword:00000050

"Position115"=dword:00000073

"Visible115"=dword:00000000

"Width115"=dword:00000050

"Position116"=dword:00000074

"Visible116"=dword:00000000

"Width116"=dword:00000050

"Position117"=dword:00000075

"Visible117"=dword:00000000

"Width117"=dword:00000050

"Position118"=dword:00000076

"Visible118"=dword:00000000

"Width118"=dword:00000050

"Position119"=dword:00000077

"Visible119"=dword:00000000

"Width119"=dword:00000050

"Position120"=dword:00000078

"Visible120"=dword:00000000

"Width120"=dword:00000050

"Position121"=dword:00000079

"Visible121"=dword:00000000

"Width121"=dword:00000050

"Position122"=dword:0000007a

"Visible122"=dword:00000000

"Width122"=dword:00000050

"Position123"=dword:0000007b

"Visible123"=dword:00000000

"Width123"=dword:00000050

"Position124"=dword:0000007c

"Visible124"=dword:00000000

"Width124"=dword:00000050

"Position125"=dword:0000007d

"Visible125"=dword:00000000

"Width125"=dword:00000050

"Position126"=dword:0000007e

"Visible126"=dword:00000000

"Width126"=dword:00000050

"Position127"=dword:0000007f

"Visible127"=dword:00000000

"Width127"=dword:00000050

"Position128"=dword:00000080

"Visible128"=dword:00000000

"Width128"=dword:00000050

"Position129"=dword:00000081

"Visible129"=dword:00000000

"Width129"=dword:00000050

"Position130"=dword:00000082

"Visible130"=dword:00000000

"Width130"=dword:00000050

"Position131"=dword:00000083

"Visible131"=dword:00000000

"Width131"=dword:00000050

"Position132"=dword:00000084

"Visible132"=dword:00000000

"Width132"=dword:00000050

"Position133"=dword:00000085

"Visible133"=dword:00000000

"Width133"=dword:00000050

"Position134"=dword:00000086

"Visible134"=dword:00000000

"Width134"=dword:00000050

"Position135"=dword:00000087

"Visible135"=dword:00000000

"Width135"=dword:00000050

"Position136"=dword:00000088

"Visible136"=dword:00000000

"Width136"=dword:00000050

"Position137"=dword:00000089

"Visible137"=dword:00000000

"Width137"=dword:00000050

"Position138"=dword:0000008a

"Visible138"=dword:00000000

"Width138"=dword:00000050

"Position139"=dword:0000008b

"Visible139"=dword:00000000

"Width139"=dword:00000050

"Position140"=dword:0000008c

"Visible140"=dword:00000000

"Width140"=dword:00000050

"Position141"=dword:0000008d

"Visible141"=dword:00000000

"Width141"=dword:00000050

"Position142"=dword:0000008e

"Visible142"=dword:00000000

"Width142"=dword:00000050

"Position143"=dword:0000008f

"Visible143"=dword:00000000

"Width143"=dword:00000050

"Position144"=dword:00000090

"Visible144"=dword:00000000

"Width144"=dword:00000050

 

[HKEY_USERS\S-1-5-21-602162358-1060284298-1202660629-1003\Software\G*e*n*i*e*"!\FM Genie Scout\Columns\Staff]

"Position0"=dword:00000000

"Visible0"=dword:00000001

"Width0"=dword:0000007d

"Position1"=dword:00000001

"Visible1"=dword:00000001

"Width1"=dword:00000064

"Position2"=dword:00000002

"Visible2"=dword:00000001

"Width2"=dword:00000064

"Position3"=dword:00000003

"Visible3"=dword:00000001

"Width3"=dword:00000069

"Position4"=dword:00000005

"Visible4"=dword:00000001

"Width4"=dword:00000028

"Position5"=dword:00000006

"Visible5"=dword:00000001

"Width5"=dword:00000028

"Position6"=dword:00000004

"Visible6"=dword:00000001

"Width6"=dword:00000028

"Position7"=dword:00000007

"Visible7"=dword:00000001

"Width7"=dword:00000050

"Position8"=dword:00000008

"Visible8"=dword:00000000

"Width8"=dword:00000050

"Position9"=dword:00000009

"Visible9"=dword:00000000

"Width9"=dword:0000004b

"Position10"=dword:0000000a

"Visible10"=dword:00000000

"Width10"=dword:0000002d

"Position11"=dword:0000000b

"Visible11"=dword:00000000

"Width11"=dword:0000003c

"Position12"=dword:0000000c

"Visible12"=dword:00000000

"Width12"=dword:0000004b

"Position13"=dword:0000000d

"Visible13"=dword:00000000

"Width13"=dword:00000064

"Position14"=dword:0000000e

"Visible14"=dword:00000000

"Width14"=dword:00000064

"Position15"=dword:0000000f

"Visible15"=dword:00000000

"Width15"=dword:0000004b

"Position16"=dword:00000010

"Visible16"=dword:00000000

"Width16"=dword:00000064

"Position17"=dword:00000011

"Visible17"=dword:00000000

"Width17"=dword:0000003c

"Position18"=dword:00000012

"Visible18"=dword:00000000

"Width18"=dword:0000004b

"Position19"=dword:00000013

"Visible19"=dword:00000000

"Width19"=dword:00000050

"Position20"=dword:00000014

"Visible20"=dword:00000000

"Width20"=dword:00000046

"Position21"=dword:00000015

"Visible21"=dword:00000000

"Width21"=dword:0000004b

"Position22"=dword:00000016

"Visible22"=dword:00000000

"Width22"=dword:00000046

"Position23"=dword:00000017

"Visible23"=dword:00000000

"Width23"=dword:00000046

"Position24"=dword:00000018

"Visible24"=dword:00000000

"Width24"=dword:0000003c

"Position25"=dword:00000019

"Visible25"=dword:00000000

"Width25"=dword:00000041

"Position26"=dword:0000001a

"Visible26"=dword:00000000

"Width26"=dword:0000003c

"Position27"=dword:0000001b

"Visible27"=dword:00000000

"Width27"=dword:00000055

"Position28"=dword:0000001c

"Visible28"=dword:00000000

"Width28"=dword:00000069

"Position29"=dword:0000001d

"Visible29"=dword:00000000

"Width29"=dword:0000006e

"Position30"=dword:0000001e

"Visible30"=dword:00000000

"Width30"=dword:00000064

"Position31"=dword:0000001f

"Visible31"=dword:00000000

"Width31"=dword:00000078

"Position32"=dword:00000020

"Visible32"=dword:00000000

"Width32"=dword:00000064

"Position33"=dword:00000021

"Visible33"=dword:00000000

"Width33"=dword:00000087

"Position34"=dword:00000022

"Visible34"=dword:00000000

"Width34"=dword:00000069

"Position35"=dword:00000023

"Visible35"=dword:00000000

"Width35"=dword:0000006e

"Position36"=dword:00000024

"Visible36"=dword:00000000

"Width36"=dword:00000073

"Position37"=dword:00000025

"Visible37"=dword:00000000

"Width37"=dword:0000004b

"Position38"=dword:00000026

"Visible38"=dword:00000000

"Width38"=dword:0000002d

"Position39"=dword:00000027

"Visible39"=dword:00000000

"Width39"=dword:00000055

"Position40"=dword:00000028

"Visible40"=dword:00000000

"Width40"=dword:00000046

"Position41"=dword:00000029

"Visible41"=dword:00000000

"Width41"=dword:0000004b

"Position42"=dword:0000002a

"Visible42"=dword:00000000

"Width42"=dword:0000003c

"Position43"=dword:0000002b

"Visible43"=dword:00000000

"Width43"=dword:00000046

"Position44"=dword:0000002c

"Visible44"=dword:00000000

"Width44"=dword:00000073

"Position45"=dword:0000002d

"Visible45"=dword:00000000

"Width45"=dword:0000004b

"Position46"=dword:0000002e

"Visible46"=dword:00000000

"Width46"=dword:00000073

"Position47"=dword:0000002f

"Visible47"=dword:00000000

"Width47"=dword:0000007d

"Position48"=dword:00000030

"Visible48"=dword:00000000

"Width48"=dword:0000006e

"Position49"=dword:00000031

"Visible49"=dword:00000000

"Width49"=dword:00000037

"Position50"=dword:00000032

"Visible50"=dword:00000000

"Width50"=dword:00000064

"Position51"=dword:00000033

"Visible51"=dword:00000000

"Width51"=dword:00000037

"Position52"=dword:00000034

"Visible52"=dword:00000000

"Width52"=dword:0000004b

"Position53"=dword:00000035

"Visible53"=dword:00000000

"Width53"=dword:00000046

"Position54"=dword:00000036

"Visible54"=dword:00000000

"Width54"=dword:00000037

"Position55"=dword:00000037

"Visible55"=dword:00000000

"Width55"=dword:0000003c

"Position56"=dword:00000038

"Visible56"=dword:00000000

"Width56"=dword:00000055

"Position57"=dword:00000039

"Visible57"=dword:00000000

"Width57"=dword:0000003c

"Position58"=dword:0000003a

"Visible58"=dword:00000000

"Width58"=dword:0000003c

"Position59"=dword:0000003b

"Visible59"=dword:00000000

"Width59"=dword:00000055

"Position60"=dword:0000003c

"Visible60"=dword:00000000

"Width60"=dword:00000046

"Position61"=dword:0000003d

"Visible61"=dword:00000000

"Width61"=dword:0000004b

"Position62"=dword:0000003e

"Visible62"=dword:00000000

"Width62"=dword:00000055

"Position63"=dword:0000003f

"Visible63"=dword:00000000

"Width63"=dword:0000005a

"Position64"=dword:00000040

"Visible64"=dword:00000000

"Width64"=dword:0000006e

"Position65"=dword:00000041

"Visible65"=dword:00000000

"Width65"=dword:00000050

"Position66"=dword:00000042

"Visible66"=dword:00000000

"Width66"=dword:00000032

"Position67"=dword:00000043

"Visible67"=dword:00000000

"Width67"=dword:00000064

"Position68"=dword:00000044

"Visible68"=dword:00000000

"Width68"=dword:0000004b

"Position69"=dword:00000045

"Visible69"=dword:00000000

"Width69"=dword:0000002d

"Position70"=dword:00000046

"Visible70"=dword:00000000

"Width70"=dword:0000004b

"Position71"=dword:00000047

"Visible71"=dword:00000000

"Width71"=dword:0000005a

"Position72"=dword:00000048

"Visible72"=dword:00000000

"Width72"=dword:0000005a

"Position73"=dword:00000049

"Visible73"=dword:00000000

"Width73"=dword:00000050

"Position74"=dword:0000004a

"Visible74"=dword:00000000

"Width74"=dword:0000004b

"Position75"=dword:0000004b

"Visible75"=dword:00000000

"Width75"=dword:00000050

"Position76"=dword:0000004c

"Visible76"=dword:00000000

"Width76"=dword:0000005a

"Position77"=dword:0000004d

"Visible77"=dword:00000000

"Width77"=dword:00000041

"Position78"=dword:0000004e

"Visible78"=dword:00000000

"Width78"=dword:00000041

"Position79"=dword:0000004f

"Visible79"=dword:00000000

"Width79"=dword:00000041

"Position80"=dword:00000050

"Visible80"=dword:00000000

"Width80"=dword:00000041

"Position81"=dword:00000051

"Visible81"=dword:00000000

"Width81"=dword:00000041

"Position82"=dword:00000052

"Visible82"=dword:00000000

"Width82"=dword:00000041

"Position83"=dword:00000053

"Visible83"=dword:00000000

"Width83"=dword:00000041

"Position84"=dword:00000054

"Visible84"=dword:00000000

"Width84"=dword:00000041

"Position85"=dword:00000055

"Visible85"=dword:00000000

"Width85"=dword:00000041

 

[HKEY_USERS\S-1-5-21-602162358-1060284298-1202660629-1003\Software\G*e*n*i*e*"!\FM Genie Scout\Rating]

"GKPositionCoef"=dword:00000000

"GKCurrentAbilityCoef"=dword:00000000

"GKCornersCoef"=dword:00000000

"GKCrossingCoef"=dword:00000000

"GKDribblingCoef"=dword:00000000

"GKFinishingCoef"=dword:00000000

"GKFirstTouchCoef"=dword:00000005

"GKFreeKicksCoef"=dword:00000000

"GKHeadingCoef"=dword:00000005

"GKLongShotsCoef"=dword:00000000

"GKLongThrowsCoef"=dword:00000000

"GKMarkingCoef"=dword:00000000

"GKPassingCoef"=dword:0000000a

"GKPenaltiesCoef"=dword:00000005

"GKTacklingCoef"=dword:0000000a

"GKTechniqueCoef"=dword:00000000

"GKLeftFootCoef"=dword:00000005

"GKRightFootCoef"=dword:00000005

"GKAggressionCoef"=dword:0000001e

"GKAnticipationCoef"=dword:0000000a

"GKBraveryCoef"=dword:0000001e

"GKComposureCoef"=dword:0000001e

"GKConcentrationCoef"=dword:00000014

"GKConsistencyCoef"=dword:00000014

"GKCreativityCoef"=dword:00000000

"GKDecisionsCoef"=dword:0000001e

"GKDeterminationCoef"=dword:00000014

"GKDirtinessCoef"=dword:fffffff6

"GKFlairCoef"=dword:00000005

"GKImportantMatchesCoef"=dword:00000014

"GKInfluenceCoef"=dword:0000000f

"GKOffTheBallCoef"=dword:00000000

"GKPositioningCoef"=dword:0000003c

"GKTeamworkCoef"=dword:0000000a

"GKWorkRateCoef"=dword:00000005

"GKAccelerationCoef"=dword:0000000a

"GKAgilityCoef"=dword:00000014

"GKBalanceCoef"=dword:00000014

"GKInjuryPronenessCoef"=dword:fffffff6

"GKJumpingCoef"=dword:00000050

"GKNaturalFitnessCoef"=dword:0000000a

"GKPaceCoef"=dword:00000000

"GKStaminaCoef"=dword:00000005

"GKStrengthCoef"=dword:0000001e

"GKVersatilityCoef"=dword:00000005

"GKAerialAbilityCoef"=dword:00000050

"GKCommandOfAreaCoef"=dword:00000032

"GKCommunicationCoef"=dword:0000003c

"GKEccentricityCoef"=dword:ffffffe7

"GKHandlingCoef"=dword:00000064

"GKKickingCoef"=dword:00000019

"GKOneOnOnesCoef"=dword:00000032

"GKReflexesCoef"=dword:00000064

"GKRushingOutCoef"=dword:0000001e

"GKTendencyToPunchCoef"=dword:ffffffe7

"GKThrowingCoef"=dword:00000019

"GKAdaptabilityCoef"=dword:0000000a

"GKAmbitionCoef"=dword:00000014

"GKControversyCoef"=dword:fffffffb

"GKLoyalityCoef"=dword:0000000a

"GKPressureCoef"=dword:00000014

"GKProfessionalismCoef"=dword:0000000f

"GKSportsmanshipCoef"=dword:0000000a

"GKTemperamentCoef"=dword:00000005

"SWPositionCoef"=dword:00000000

"SWCurrentAbilityCoef"=dword:00000000

"SWCornersCoef"=dword:0000000a

"SWCrossingCoef"=dword:00000005

"SWDribblingCoef"=dword:00000005

"SWFinishingCoef"=dword:00000005

"SWFirstTouchCoef"=dword:00000014

"SWFreeKicksCoef"=dword:0000000a

"SWHeadingCoef"=dword:00000064

"SWLongShotsCoef"=dword:00000005

"SWLongThrowsCoef"=dword:00000005

"SWMarkingCoef"=dword:00000064

"SWPassingCoef"=dword:00000014

"SWPenaltiesCoef"=dword:00000005

"SWTacklingCoef"=dword:00000064

"SWTechniqueCoef"=dword:0000000f

"SWLeftFootCoef"=dword:0000000a

"SWRightFootCoef"=dword:0000000a

"SWAggressionCoef"=dword:0000000f

"SWAnticipationCoef"=dword:00000014

"SWBraveryCoef"=dword:00000028

"SWComposureCoef"=dword:00000028

"SWConcentrationCoef"=dword:00000028

"SWConsistencyCoef"=dword:00000014

"SWCreativityCoef"=dword:00000005

"SWDecisionsCoef"=dword:0000001e

"SWDeterminationCoef"=dword:00000014

"SWDirtinessCoef"=dword:ffffffe7

"SWFlairCoef"=dword:00000005

"SWImportantMatchesCoef"=dword:00000014

"SWInfluenceCoef"=dword:0000000f

"SWOffTheBallCoef"=dword:00000005

"SWPositioningCoef"=dword:00000064

"SWTeamworkCoef"=dword:00000028

"SWWorkRateCoef"=dword:0000000a

"SWAccelerationCoef"=dword:00000019

"SWAgilityCoef"=dword:00000005

"SWBalanceCoef"=dword:00000014

"SWInjuryPronenessCoef"=dword:fffffff6

"SWJumpingCoef"=dword:00000050

"SWNaturalFitnessCoef"=dword:0000000a

"SWPaceCoef"=dword:00000019

"SWStaminaCoef"=dword:0000000f

"SWStrengthCoef"=dword:0000003c

"SWVersatilityCoef"=dword:00000005

"SWAerialAbilityCoef"=dword:00000000

"SWCommandOfAreaCoef"=dword:00000000

"SWCommunicationCoef"=dword:00000000

"SWEccentricityCoef"=dword:00000000

"SWHandlingCoef"=dword:00000000

"SWKickingCoef"=dword:00000000

"SWOneOnOnesCoef"=dword:00000005

"SWReflexesCoef"=dword:00000005

"SWRushingOutCoef"=dword:00000000

"SWTendencyToPunchCoef"=dword:00000000

"SWThrowingCoef"=dword:00000000

"SWAdaptabilityCoef"=dword:0000000a

"SWAmbitionCoef"=dword:00000014

"SWControversyCoef"=dword:fffffffb

"SWLoyalityCoef"=dword:0000000a

"SWPressureCoef"=dword:00000014

"SWProfessionalismCoef"=dword:0000000f

"SWSportsmanshipCoef"=dword:0000000a

"SWTemperamentCoef"=dword:00000005

"CBPositionCoef"=dword:00000000

"CBCurrentAbilityCoef"=dword:00000000

"CBCornersCoef"=dword:00000014

"CBCrossingCoef"=dword:0000000a

"CBDribblingCoef"=dword:00000005

"CBFinishingCoef"=dword:00000005

"CBFirstTouchCoef"=dword:00000014

"CBFreeKicksCoef"=dword:00000014

"CBHeadingCoef"=dword:00000064

"CBLongShotsCoef"=dword:00000005

"CBLongThrowsCoef"=dword:00000005

"CBMarkingCoef"=dword:00000050

"CBPassingCoef"=dword:0000001e

"CBPenaltiesCoef"=dword:00000005

"CBTacklingCoef"=dword:00000064

"CBTechniqueCoef"=dword:0000000f

"CBLeftFootCoef"=dword:0000000a

"CBRightFootCoef"=dword:0000000a

"CBAggressionCoef"=dword:0000000f

"CBAnticipationCoef"=dword:00000014

"CBBraveryCoef"=dword:00000028

"CBComposureCoef"=dword:0000001e

"CBConcentrationCoef"=dword:0000001e

"CBConsistencyCoef"=dword:00000014

"CBCreativityCoef"=dword:00000005

"CBDecisionsCoef"=dword:0000001e

"CBDeterminationCoef"=dword:00000014

"CBDirtinessCoef"=dword:ffffffec

"CBFlairCoef"=dword:00000005

"CBImportantMatchesCoef"=dword:00000014

"CBInfluenceCoef"=dword:0000000f

"CBOffTheBallCoef"=dword:0000000a

"CBPositioningCoef"=dword:00000050

"CBTeamworkCoef"=dword:00000028

"CBWorkRateCoef"=dword:0000000a

"CBAccelerationCoef"=dword:00000023

"CBAgilityCoef"=dword:00000005

"CBBalanceCoef"=dword:00000014

"CBInjuryPronenessCoef"=dword:fffffff6

"CBJumpingCoef"=dword:00000050

"CBNaturalFitnessCoef"=dword:0000000a

"CBPaceCoef"=dword:00000023

"CBStaminaCoef"=dword:00000014

"CBStrengthCoef"=dword:00000032

"CBVersatilityCoef"=dword:00000005

"CBAerialAbilityCoef"=dword:00000000

"CBCommandOfAreaCoef"=dword:00000000

"CBCommunicationCoef"=dword:00000000

"CBEccentricityCoef"=dword:00000000

"CBHandlingCoef"=dword:00000000

"CBKickingCoef"=dword:00000000

"CBOneOnOnesCoef"=dword:00000005

"CBReflexesCoef"=dword:00000005

"CBRushingOutCoef"=dword:00000000

"CBTendencyToPunchCoef"=dword:00000000

"CBThrowingCoef"=dword:00000000

"CBAdaptabilityCoef"=dword:0000000a

"CBAmbitionCoef"=dword:00000014

"CBControversyCoef"=dword:fffffffb

"CBLoyalityCoef"=dword:0000000a

"CBPressureCoef"=dword:00000014

"CBProfessionalismCoef"=dword:0000000f

"CBSportsmanshipCoef"=dword:0000000a

"CBTemperamentCoef"=dword:00000005

"FBPositionCoef"=dword:00000000

"FBCurrentAbilityCoef"=dword:00000000

"FBCornersCoef"=dword:00000014

"FBCrossingCoef"=dword:00000023

"FBDribblingCoef"=dword:0000001e

"FBFinishingCoef"=dword:0000000a

"FBFirstTouchCoef"=dword:00000014

"FBFreeKicksCoef"=dword:00000014

"FBHeadingCoef"=dword:0000003c

"FBLongShotsCoef"=dword:0000000a

"FBLongThrowsCoef"=dword:0000000a

"FBMarkingCoef"=dword:00000050

"FBPassingCoef"=dword:00000023

"FBPenaltiesCoef"=dword:00000005

"FBTacklingCoef"=dword:00000064

"FBTechniqueCoef"=dword:0000001e

"FBLeftFootCoef"=dword:0000000a

"FBRightFootCoef"=dword:0000000a

"FBAggressionCoef"=dword:0000000f

"FBAnticipationCoef"=dword:0000003c

"FBBraveryCoef"=dword:00000019

"FBComposureCoef"=dword:00000019

"FBConcentrationCoef"=dword:0000001e

"FBConsistencyCoef"=dword:00000014

"FBCreativityCoef"=dword:0000000a

"FBDecisionsCoef"=dword:00000019

"FBDeterminationCoef"=dword:00000014

"FBDirtinessCoef"=dword:fffffff1

"FBFlairCoef"=dword:00000005

"FBImportantMatchesCoef"=dword:00000014

"FBInfluenceCoef"=dword:0000000f

"FBOffTheBallCoef"=dword:0000000f

"FBPositioningCoef"=dword:00000050

"FBTeamworkCoef"=dword:00000014

"FBWorkRateCoef"=dword:00000014

"FBAccelerationCoef"=dword:00000032

"FBAgilityCoef"=dword:00000005

"FBBalanceCoef"=dword:00000014

"FBInjuryPronenessCoef"=dword:fffffff6

"FBJumpingCoef"=dword:0000003c

"FBNaturalFitnessCoef"=dword:0000000a

"FBPaceCoef"=dword:00000032

"FBStaminaCoef"=dword:0000001e

"FBStrengthCoef"=dword:00000028

"FBVersatilityCoef"=dword:00000005

"FBAerialAbilityCoef"=dword:00000000

"FBCommandOfAreaCoef"=dword:00000000

"FBCommunicationCoef"=dword:00000000

"FBEccentricityCoef"=dword:00000000

"FBHandlingCoef"=dword:00000000

"FBKickingCoef"=dword:00000000

"FBOneOnOnesCoef"=dword:00000005

"FBReflexesCoef"=dword:00000005

"FBRushingOutCoef"=dword:00000000

"FBTendencyToPunchCoef"=dword:00000000

"FBThrowingCoef"=dword:00000000

"FBAdaptabilityCoef"=dword:0000000a

"FBAmbitionCoef"=dword:00000014

"FBControversyCoef"=dword:fffffffb

"FBLoyalityCoef"=dword:0000000a

"FBPressureCoef"=dword:00000014

"FBProfessionalismCoef"=dword:0000000f

"FBSportsmanshipCoef"=dword:0000000a

"FBTemperamentCoef"=dword:00000005

"WBPositionCoef"=dword:00000000

"WBCurrentAbilityCoef"=dword:00000000

"WBCornersCoef"=dword:00000014

"WBCrossingCoef"=dword:0000004b

"WBDribblingCoef"=dword:0000003c

"WBFinishingCoef"=dword:0000001e

"WBFirstTouchCoef"=dword:00000019

"WBFreeKicksCoef"=dword:00000014

"WBHeadingCoef"=dword:00000019

"WBLongShotsCoef"=dword:0000000f

"WBLongThrowsCoef"=dword:0000000f

"WBMarkingCoef"=dword:0000003c

"WBPassingCoef"=dword:00000028

"WBPenaltiesCoef"=dword:00000005

"WBTacklingCoef"=dword:00000050

"WBTechniqueCoef"=dword:00000032

"WBLeftFootCoef"=dword:0000000a

"WBRightFootCoef"=dword:0000000a

"WBAggressionCoef"=dword:0000000a

"WBAnticipationCoef"=dword:00000032

"WBBraveryCoef"=dword:0000000f

"WBComposureCoef"=dword:00000014

"WBConcentrationCoef"=dword:00000019

"WBConsistencyCoef"=dword:00000014

"WBCreativityCoef"=dword:00000014

"WBDecisionsCoef"=dword:00000014

"WBDeterminationCoef"=dword:00000014

"WBDirtinessCoef"=dword:fffffff6

"WBFlairCoef"=dword:0000000a

"WBImportantMatchesCoef"=dword:00000014

"WBInfluenceCoef"=dword:0000000a

"WBOffTheBallCoef"=dword:00000014

"WBPositioningCoef"=dword:0000003c

"WBTeamworkCoef"=dword:00000014

"WBWorkRateCoef"=dword:0000001e

"WBAccelerationCoef"=dword:00000050

"WBAgilityCoef"=dword:00000005

"WBBalanceCoef"=dword:0000000f

"WBInjuryPronenessCoef"=dword:fffffff6

"WBJumpingCoef"=dword:00000019

"WBNaturalFitnessCoef"=dword:0000000a

"WBPaceCoef"=dword:0000005a

"WBStaminaCoef"=dword:0000004b

"WBStrengthCoef"=dword:00000028

"WBVersatilityCoef"=dword:00000005

"WBAerialAbilityCoef"=dword:00000000

"WBCommandOfAreaCoef"=dword:00000000

"WBCommunicationCoef"=dword:00000000

"WBEccentricityCoef"=dword:00000000

"WBHandlingCoef"=dword:00000000

"WBKickingCoef"=dword:00000000

"WBOneOnOnesCoef"=dword:00000005

"WBReflexesCoef"=dword:00000005

"WBRushingOutCoef"=dword:00000000

"WBTendencyToPunchCoef"=dword:00000000

"WBThrowingCoef"=dword:00000000

"WBAdaptabilityCoef"=dword:0000000a

"WBAmbitionCoef"=dword:00000014

"WBControversyCoef"=dword:fffffffb

"WBLoyalityCoef"=dword:0000000a

"WBPressureCoef"=dword:00000014

"WBProfessionalismCoef"=dword:0000000f

"WBSportsmanshipCoef"=dword:0000000a

"WBTemperamentCoef"=dword:00000005

"DMPositionCoef"=dword:00000000

"DMCurrentAbilityCoef"=dword:00000000

"DMCornersCoef"=dword:00000014

"DMCrossingCoef"=dword:00000028

"DMDribblingCoef"=dword:00000019

"DMFinishingCoef"=dword:0000001e

"DMFirstTouchCoef"=dword:00000019

"DMFreeKicksCoef"=dword:00000014

"DMHeadingCoef"=dword:00000032

"DMLongShotsCoef"=dword:00000014

"DMLongThrowsCoef"=dword:0000000a

"DMMarkingCoef"=dword:0000004b

"DMPassingCoef"=dword:00000032

"DMPenaltiesCoef"=dword:00000005

"DMTacklingCoef"=dword:00000050

"DMTechniqueCoef"=dword:0000001e

"DMLeftFootCoef"=dword:0000000a

"DMRightFootCoef"=dword:0000000a

"DMAggressionCoef"=dword:00000028

"DMAnticipationCoef"=dword:00000028

"DMBraveryCoef"=dword:0000000f

"DMComposureCoef"=dword:00000014

"DMConcentrationCoef"=dword:00000019

"DMConsistencyCoef"=dword:00000014

"DMCreativityCoef"=dword:00000019

"DMDecisionsCoef"=dword:00000014

"DMDeterminationCoef"=dword:00000014

"DMDirtinessCoef"=dword:fffffff6

"DMFlairCoef"=dword:0000000f

"DMImportantMatchesCoef"=dword:00000014

"DMInfluenceCoef"=dword:0000000f

"DMOffTheBallCoef"=dword:00000019

"DMPositioningCoef"=dword:0000003c

"DMTeamworkCoef"=dword:0000001e

"DMWorkRateCoef"=dword:0000003c

"DMAccelerationCoef"=dword:00000028

"DMAgilityCoef"=dword:00000005

"DMBalanceCoef"=dword:0000000f

"DMInjuryPronenessCoef"=dword:fffffff6

"DMJumpingCoef"=dword:00000028

"DMNaturalFitnessCoef"=dword:0000000a

"DMPaceCoef"=dword:00000023

"DMStaminaCoef"=dword:00000041

"DMStrengthCoef"=dword:00000032

"DMVersatilityCoef"=dword:00000005

"DMAerialAbilityCoef"=dword:00000000

"DMCommandOfAreaCoef"=dword:00000000

"DMCommunicationCoef"=dword:00000000

"DMEccentricityCoef"=dword:00000000

"DMHandlingCoef"=dword:00000000

"DMKickingCoef"=dword:00000000

"DMOneOnOnesCoef"=dword:00000005

"DMReflexesCoef"=dword:00000005

"DMRushingOutCoef"=dword:00000000

"DMTendencyToPunchCoef"=dword:00000000

"DMThrowingCoef"=dword:00000000

"DMAdaptabilityCoef"=dword:0000000a

"DMAmbitionCoef"=dword:00000014

"DMControversyCoef"=dword:fffffffb

"DMLoyalityCoef"=dword:0000000a

"DMPressureCoef"=dword:00000014

"DMProfessionalismCoef"=dword:0000000f

"DMSportsmanshipCoef"=dword:0000000a

"DMTemperamentCoef"=dword:00000005

"MPositionCoef"=dword:00000000

"MCurrentAbilityCoef"=dword:00000000

"MCornersCoef"=dword:00000019

"MCrossingCoef"=dword:00000032

"MDribblingCoef"=dword:00000032

"MFinishingCoef"=dword:00000028

"MFirstTouchCoef"=dword:0000001e

"MFreeKicksCoef"=dword:00000014

"MHeadingCoef"=dword:00000028

"MLongShotsCoef"=dword:00000019

"MLongThrowsCoef"=dword:0000000a

"MMarkingCoef"=dword:00000028

"MPassingCoef"=dword:0000004b

"MPenaltiesCoef"=dword:00000005

"MTacklingCoef"=dword:00000028

"MTechniqueCoef"=dword:00000032

"MLeftFootCoef"=dword:0000000a

"MRightFootCoef"=dword:0000000a

"MAggressionCoef"=dword:0000001e

"MAnticipationCoef"=dword:00000028

"MBraveryCoef"=dword:0000000a

"MComposureCoef"=dword:00000014

"MConcentrationCoef"=dword:00000014

"MConsistencyCoef"=dword:00000014

"MCreativityCoef"=dword:0000003c

"MDecisionsCoef"=dword:00000014

"MDeterminationCoef"=dword:00000014

"MDirtinessCoef"=dword:fffffffb

"MFlairCoef"=dword:00000014

"MImportantMatchesCoef"=dword:00000014

"MInfluenceCoef"=dword:0000000a

"MOffTheBallCoef"=dword:0000001e

"MPositioningCoef"=dword:00000028

"MTeamworkCoef"=dword:00000023

"MWorkRateCoef"=dword:00000032

"MAccelerationCoef"=dword:0000002d

"MAgilityCoef"=dword:00000005

"MBalanceCoef"=dword:0000000a

"MInjuryPronenessCoef"=dword:fffffff6

"MJumpingCoef"=dword:0000001e

"MNaturalFitnessCoef"=dword:0000000a

"MPaceCoef"=dword:00000028

"MStaminaCoef"=dword:0000003c

"MStrengthCoef"=dword:00000023

"MVersatilityCoef"=dword:00000005

"MAerialAbilityCoef"=dword:00000000

"MCommandOfAreaCoef"=dword:00000000

"MCommunicationCoef"=dword:00000000

"MEccentricityCoef"=dword:00000000

"MHandlingCoef"=dword:00000000

"MKickingCoef"=dword:00000000

"MOneOnOnesCoef"=dword:00000005

"MReflexesCoef"=dword:00000005

"MRushingOutCoef"=dword:00000000

"MTendencyToPunchCoef"=dword:00000000

"MThrowingCoef"=dword:00000000

"MAdaptabilityCoef"=dword:0000000a

"MAmbitionCoef"=dword:00000014

"MControversyCoef"=dword:fffffffb

"MLoyalityCoef"=dword:0000000a

"MPressureCoef"=dword:00000014

"MProfessionalismCoef"=dword:0000000f

"MSportsmanshipCoef"=dword:0000000a

"MTemperamentCoef"=dword:00000005

"AMPositionCoef"=dword:00000000

"AMCurrentAbilityCoef"=dword:00000000

"AMCornersCoef"=dword:00000019

"AMCrossingCoef"=dword:00000046

"AMDribblingCoef"=dword:00000046

"AMFinishingCoef"=dword:00000032

"AMFirstTouchCoef"=dword:00000028

"AMFreeKicksCoef"=dword:00000014

"AMHeadingCoef"=dword:0000001e

"AMLongShotsCoef"=dword:0000001e

"AMLongThrowsCoef"=dword:00000005

"AMMarkingCoef"=dword:0000000f

"AMPassingCoef"=dword:00000064

"AMPenaltiesCoef"=dword:00000005

"AMTacklingCoef"=dword:0000000a

"AMTechniqueCoef"=dword:00000050

"AMLeftFootCoef"=dword:0000000a

"AMRightFootCoef"=dword:0000000a

"AMAggressionCoef"=dword:0000000a

"AMAnticipationCoef"=dword:00000023

"AMBraveryCoef"=dword:0000000a

"AMComposureCoef"=dword:00000014

"AMConcentrationCoef"=dword:00000014

"AMConsistencyCoef"=dword:00000014

"AMCreativityCoef"=dword:00000064

"AMDecisionsCoef"=dword:00000014

"AMDeterminationCoef"=dword:00000014

"AMDirtinessCoef"=dword:fffffffb

"AMFlairCoef"=dword:0000001e

"AMImportantMatchesCoef"=dword:00000014

"AMInfluenceCoef"=dword:0000000a

"AMOffTheBallCoef"=dword:00000028

"AMPositioningCoef"=dword:00000014

"AMTeamworkCoef"=dword:00000028

"AMWorkRateCoef"=dword:00000019

"AMAccelerationCoef"=dword:00000032

"AMAgilityCoef"=dword:0000000a

"AMBalanceCoef"=dword:0000000a

"AMInjuryPronenessCoef"=dword:fffffff6

"AMJumpingCoef"=dword:00000014

"AMNaturalFitnessCoef"=dword:0000000a

"AMPaceCoef"=dword:00000032

"AMStaminaCoef"=dword:00000028

"AMStrengthCoef"=dword:00000014

"AMVersatilityCoef"=dword:00000005

"AMAerialAbilityCoef"=dword:00000000

"AMCommandOfAreaCoef"=dword:00000000

"AMCommunicationCoef"=dword:00000000

"AMEccentricityCoef"=dword:00000000

"AMHandlingCoef"=dword:00000000

"AMKickingCoef"=dword:00000000

"AMOneOnOnesCoef"=dword:00000005

"AMReflexesCoef"=dword:00000005

"AMRushingOutCoef"=dword:00000000

"AMTendencyToPunchCoef"=dword:00000000

"AMThrowingCoef"=dword:00000000

"AMAdaptabilityCoef"=dword:0000000a

"AMAmbitionCoef"=dword:00000014

"AMControversyCoef"=dword:fffffffb

"AMLoyalityCoef"=dword:0000000a

"AMPressureCoef"=dword:00000014

"AMProfessionalismCoef"=dword:0000000f

"AMSportsmanshipCoef"=dword:0000000a

"AMTemperamentCoef"=dword:00000005

"WPositionCoef"=dword:00000000

"WCurrentAbilityCoef"=dword:00000000

"WCornersCoef"=dword:00000019

"WCrossingCoef"=dword:00000064

"WDribblingCoef"=dword:00000064

"WFinishingCoef"=dword:0000003c

"WFirstTouchCoef"=dword:0000001e

"WFreeKicksCoef"=dword:00000014

"WHeadingCoef"=dword:00000014

"WLongShotsCoef"=dword:00000019

"WLongThrowsCoef"=dword:0000000a

"WMarkingCoef"=dword:00000019

"WPassingCoef"=dword:0000003c

"WPenaltiesCoef"=dword:00000005

"WTacklingCoef"=dword:00000014

"WTechniqueCoef"=dword:00000050

"WLeftFootCoef"=dword:0000000a

"WRightFootCoef"=dword:0000000a

"WAggressionCoef"=dword:0000000a

"WAnticipationCoef"=dword:00000023

"WBraveryCoef"=dword:0000000a

"WComposureCoef"=dword:00000014

"WConcentrationCoef"=dword:00000014

"WConsistencyCoef"=dword:00000014

"WCreativityCoef"=dword:00000032

"WDecisionsCoef"=dword:0000000f

"WDeterminationCoef"=dword:00000014

"WDirtinessCoef"=dword:fffffffb

"WFlairCoef"=dword:0000001e

"WImportantMatchesCoef"=dword:00000014

"WInfluenceCoef"=dword:00000005

"WOffTheBallCoef"=dword:00000032

"WPositioningCoef"=dword:00000019

"WTeamworkCoef"=dword:0000001e

"WWorkRateCoef"=dword:0000001e

"WAccelerationCoef"=dword:00000050

"WAgilityCoef"=dword:00000014

"WBalanceCoef"=dword:0000000a

"WInjuryPronenessCoef"=dword:fffffff6

"WJumpingCoef"=dword:00000014

"WNaturalFitnessCoef"=dword:0000000a

"WPaceCoef"=dword:00000064

"WStaminaCoef"=dword:00000032

"WStrengthCoef"=dword:00000014

"WVersatilityCoef"=dword:00000005

"WAerialAbilityCoef"=dword:00000000

"WCommandOfAreaCoef"=dword:00000000

"WCommunicationCoef"=dword:00000000

"WEccentricityCoef"=dword:00000000

"WHandlingCoef"=dword:00000000

"WKickingCoef"=dword:00000000

"WOneOnOnesCoef"=dword:00000005

"WReflexesCoef"=dword:00000005

"WRushingOutCoef"=dword:00000000

"WTendencyToPunchCoef"=dword:00000000

"WThrowingCoef"=dword:00000000

"WAdaptabilityCoef"=dword:0000000a

"WAmbitionCoef"=dword:00000014

"WControversyCoef"=dword:fffffffb

"WLoyalityCoef"=dword:0000000a

"WPressureCoef"=dword:00000014

"WProfessionalismCoef"=dword:0000000f

"WSportsmanshipCoef"=dword:0000000a

"WTemperamentCoef"=dword:00000005

"FSTPositionCoef"=dword:00000000

"FSTCurrentAbilityCoef"=dword:00000000

"FSTCornersCoef"=dword:00000014

"FSTCrossingCoef"=dword:0000001e

"FSTDribblingCoef"=dword:00000050

"FSTFinishingCoef"=dword:00000064

"FSTFirstTouchCoef"=dword:00000028

"FSTFreeKicksCoef"=dword:00000014

"FSTHeadingCoef"=dword:0000003c

"FSTLongShotsCoef"=dword:0000001e

"FSTLongThrowsCoef"=dword:00000005

"FSTMarkingCoef"=dword:0000000a

"FSTPassingCoef"=dword:00000028

"FSTPenaltiesCoef"=dword:00000005

"FSTTacklingCoef"=dword:0000000a

"FSTTechniqueCoef"=dword:0000004b

"FSTLeftFootCoef"=dword:0000000a

"FSTRightFootCoef"=dword:0000000a

"FSTAggressionCoef"=dword:00000014

"FSTAnticipationCoef"=dword:00000014

"FSTBraveryCoef"=dword:0000000f

"FSTComposureCoef"=dword:00000014

"FSTConcentrationCoef"=dword:00000014

"FSTConsistencyCoef"=dword:00000014

"FSTCreativityCoef"=dword:00000032

"FSTDecisionsCoef"=dword:0000000a

"FSTDeterminationCoef"=dword:00000014

"FSTDirtinessCoef"=dword:fffffffb

"FSTFlairCoef"=dword:00000019

"FSTImportantMatchesCoef"=dword:00000014

"FSTInfluenceCoef"=dword:00000005

"FSTOffTheBallCoef"=dword:0000003c

"FSTPositioningCoef"=dword:0000000a

"FSTTeamworkCoef"=dword:0000000a

"FSTWorkRateCoef"=dword:0000000a

"FSTAccelerationCoef"=dword:00000064

"FSTAgilityCoef"=dword:0000001e

"FSTBalanceCoef"=dword:00000014

"FSTInjuryPronenessCoef"=dword:fffffff6

"FSTJumpingCoef"=dword:00000014

"FSTNaturalFitnessCoef"=dword:0000000a

"FSTPaceCoef"=dword:0000005a

"FSTStaminaCoef"=dword:00000014

"FSTStrengthCoef"=dword:00000014

"FSTVersatilityCoef"=dword:00000005

"FSTAerialAbilityCoef"=dword:00000000

"FSTCommandOfAreaCoef"=dword:00000000

"FSTCommunicationCoef"=dword:00000000

"FSTEccentricityCoef"=dword:00000000

"FSTHandlingCoef"=dword:00000000

"FSTKickingCoef"=dword:00000000

"FSTOneOnOnesCoef"=dword:00000005

"FSTReflexesCoef"=dword:00000005

"FSTRushingOutCoef"=dword:00000000

"FSTTendencyToPunchCoef"=dword:00000000

"FSTThrowingCoef"=dword:00000000

"FSTAdaptabilityCoef"=dword:0000000a

"FSTAmbitionCoef"=dword:00000014

"FSTControversyCoef"=dword:fffffffb

"FSTLoyalityCoef"=dword:0000000a

"FSTPressureCoef"=dword:00000014

"FSTProfessionalismCoef"=dword:0000000f

"FSTSportsmanshipCoef"=dword:0000000a

"FSTTemperamentCoef"=dword:00000005

"TSTPositionCoef"=dword:00000000

"TSTCurrentAbilityCoef"=dword:00000000

"TSTCornersCoef"=dword:00000014

"TSTCrossingCoef"=dword:0000001e

"TSTDribblingCoef"=dword:0000003c

"TSTFinishingCoef"=dword:0000003c

"TSTFirstTouchCoef"=dword:00000028

"TSTFreeKicksCoef"=dword:00000014

"TSTHeadingCoef"=dword:00000064

"TSTLongShotsCoef"=dword:0000001e

"TSTLongThrowsCoef"=dword:00000005

"TSTMarkingCoef"=dword:0000000a

"TSTPassingCoef"=dword:0000001e

"TSTPenaltiesCoef"=dword:00000005

"TSTTacklingCoef"=dword:0000000a

"TSTTechniqueCoef"=dword:00000028

"TSTLeftFootCoef"=dword:0000000a

"TSTRightFootCoef"=dword:0000000a

"TSTAggressionCoef"=dword:00000014

"TSTAnticipationCoef"=dword:00000014

"TSTBraveryCoef"=dword:00000014

"TSTComposureCoef"=dword:00000014

"TSTConcentrationCoef"=dword:00000014

"TSTConsistencyCoef"=dword:00000014

"TSTCreativityCoef"=dword:00000028

"TSTDecisionsCoef"=dword:0000000a

"TSTDeterminationCoef"=dword:00000014

"TSTDirtinessCoef"=dword:fffffffb

"TSTFlairCoef"=dword:00000019

"TSTImportantMatchesCoef"=dword:00000014

"TSTInfluenceCoef"=dword:00000005

"TSTOffTheBallCoef"=dword:00000050

"TSTPositioningCoef"=dword:0000000a

"TSTTeamworkCoef"=dword:0000000a

"TSTWorkRateCoef"=dword:0000000a

"TSTAccelerationCoef"=dword:00000028

"TSTAgilityCoef"=dword:00000014

"TSTBalanceCoef"=dword:00000014

"TSTInjuryPronenessCoef"=dword:fffffff6

"TSTJumpingCoef"=dword:00000064

"TSTNaturalFitnessCoef"=dword:0000000a

"TSTPaceCoef"=dword:00000023

"TSTStaminaCoef"=dword:0000000f

"TSTStrengthCoef"=dword:00000050

"TSTVersatilityCoef"=dword:00000005

"TSTAerialAbilityCoef"=dword:00000000

"TSTCommandOfAreaCoef"=dword:00000000

"TSTCommunicationCoef"=dword:00000000

"TSTEccentricityCoef"=dword:00000000

"TSTHandlingCoef"=dword:00000000

"TSTKickingCoef"=dword:00000000

"TSTOneOnOnesCoef"=dword:00000005

"TSTReflexesCoef"=dword:00000005

"TSTRushingOutCoef"=dword:00000000

"TSTTendencyToPunchCoef"=dword:00000000

"TSTThrowingCoef"=dword:00000000

"TSTAdaptabilityCoef"=dword:0000000a

"TSTAmbitionCoef"=dword:00000014

"TSTControversyCoef"=dword:fffffffb

"TSTLoyalityCoef"=dword:0000000a

"TSTPressureCoef"=dword:00000014

"TSTProfessionalismCoef"=dword:0000000f

"TSTSportsmanshipCoef"=dword:0000000a

"TSTTemperamentCoef"=dword:00000005

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]

"OODEFRAG08.00.00.01WORKSTATION"="8180AC66A30F66398D79CC55AA40C5F3373699DBDB2BA53BEAD482D996BD879B414D7879E34

2EEEC0BB225896EE24629378873E6544D895F1026E8E93F54C83132234F754F317C5E6CE1A90C5F4

9

9DEA5D1D7F70890CA0426A09F5640ADAAD81078BB5E86486B23E42F925976655C867B16D6F877223

5

D34242360489B863921A4F38861138FCC01CFCF376C618D5396F75847BD79F1BF4C1C7BB0970DAE8

3

FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C

F

EBC9E127BECC74C8EDD5E5BE2F6E6678EDD5E5BE2F6E667A6A0AC4980AC7933A9C6AECB7A5D1407D

E

81C55C843BF6A1CFA31D5663D59A7CFDA1AC15BB039EC73C9769E0BD0F099BB9A09B94B577A6512C

C

686324DC27346125195CC46AF1368044EA0BFD92FE09B8B7E41B999B6036618862F916BD31B74FCF

4

BBF407A07DE67915C9D898FB7D7462156AC6DA984459C3F87676D8D6C397ABE04734AB72250A6F1D

F

71755FEDD420E10338EA636453A20E61FB6B511BE54521B45056236F6AAF6C89D3A7137AAB325CF1

B

B32E1A842D634E517BA2BA8661685E26355FF104B5EBAF965752162B8801E982B02744A4E707DF97

4

24800B58C29183E695B1E01ABE79E9ED4DE01CF993EA531D14BA6EC384B82625D4E800CB6136DC51

7

102847244B9358EF83D3A9D03D00CFB6D8A7487A2F4F047267CFECD06832D989BDEF5346BAC2C736

3

3DA6DAAA42A6F55102345A37C14B4FB4377E16733F1F8DEA84B46501F13580D61D8763BDB0880773

8

6896BABA50104719F01694BB6B090B1803649323A1D52C0703C1A792B15AB79A3A155BB8BB14F425

A

F59879390D2D3D75498F338BD721F1F84712C3773B68784CF39330940A57D231420868B090155B77

0

EC6D11E843462D7BCB9480CF34AC4653A20781780CA7D7F80169BB2E25FC8B7B148A275C41D33379

3

AC4677955BF38E4952F3C39F0930A29B81C008EB40E2910636EB6034AD1BB04CBB1A95A002CB2977

6

93180766B08464A69F77ED071EEE3AD14D3F7C20995295B067C50E7F349270D2B6B5995E47145F50

8

604C1D69ABA7A7E70041D675C871C3F8284E481EBBA6DD72BFCE0AF6F8C425BF94E34C7BFF0C629B

6

8EEAA91D717AF2B66CE2983B11FA589616FD1797C4281538BFA5DBA1F808B68FABA3D53526056748

4

CC2BC61FD7E4CB57144338197A2ED8D09A67C273E9A2F8069B3BA4EC507601434EE456C6F4D4E574

0

408743623478E11C7EF58AB050C1A39D4190EAEDBEC107F888724357B21D5FF72D7B4689556C2CB1

2

778D9C3ECBD265F236DDB445C18A2B5E4671D2CEE9BC4537E5A47F1F2A7F74450987A6F2C18488BE

3

52C9F1888F7EC50CA988E53250915057D3D908EB286612DB4E202FB7E960C2441D32245B7A454AB9

2

2E483A7E6E6B113FAE2B89492AB9F"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'explorer.exe'(2656)

c:\windows\system32\WININET.dll

c:\arquivos de programas\RocketDock\RocketDock.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\arquivos de programas\LAVASOFT\AD-AWARE\AAWSERVICE.EXE

c:\arquivos de programas\AVIRA\ANTIVIR DESKTOP\AVGUARD.EXE

c:\arquivos de programas\BONJOUR\MDNSRESPONDER.EXE

c:\arquivos de programas\ARQUIVOS COMUNS\MICROSOFT SHARED\VS7DEBUG\MDM.EXE

c:\arquivos de programas\ARQUIVOS COMUNS\NERO\NERO BACKITUP 4\NBSERVICE.EXE

c:\arquivos de programas\SPEEDBIT VIDEO ACCELERATOR\VIDEOACCELERATORSERVICE.EXE

c:\windows\SYSTEM32\WBEM\UNSECAPP.EXE

c:\arquivos de programas\SPEEDBIT VIDEO ACCELERATOR\VIDEOACCELERATORENGINE.EXE

.

**************************************************************************

.

Tempo para conclusão: 2009-06-26 17:13 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-06-26 20:13

 

Pré-execução: 12 pasta(s) 13.867.450.368 bytes disponíveis

Pós execução: 12 pasta(s) 13.756.301.312 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin

 

1675 --- E O F --- 2009-06-24 06:04

 

 

e o novo log do HijackThis:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 17:48:07, on 26/6/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\svchost.exe

G:\opera.exe

C:\Documents and Settings\administrator\Desktop\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll

O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe"

O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: windows_system_32-dll.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -

O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - (no file)

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - (no file)

O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

 

--

End of file - 7999 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

:thumbsup: Mais outros problemas foram removidos pelo Combofix.

 

:seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

- Faça o download do Malwarebytes Anti-Malware.

* Faça a instalação dando um duplo clique em "mbam-setup.exe";

*Selecione a linguagem Português (Brasil)

*Selecione apenas a caixa: "Atualizar MalwareBytes'Anti-Malware"

*Se alguma atualização existir, o download será automático

*Não faça ainda scan!!!

*Reinicie o PC em Modo de Segurança (apertando a tecla F8 (ou a tecla F5 em alguns computadores) repetidas vezes quando o computador estiver reiniciando e escolhendo a opção Modo Seguro ou Modo de Segurança).

* Se não possível executar o computador em Modo Seguro, faça o escaneamento no modo normal

*Execute o programa MalwareBytes'Anti-Malware e clique na aba: "Verificação", selecione a opção "Verificação completa"

*Clique no botão: "Verificar"

* Marque todas as partes do computador que você deseja escanear e clique no botão: “Iniciar verificação”

*Ao término do scan, clique em "OK" > "Mostrar Resultados"

*Selecione todas as entradas e clique em "Remover Selecionados"

*Após a remoção poderá ser interrogado se deseja remover objetos da memória. Clique "SIM"

*Um log será apresentado com o resultado das ações

*Alguns malwares são rebeldes e necessitam de uma reinicialização para a remoção. Caso isto seja solicitado, clique para reiniciar o PC.

*Ao término do processo, reinicie o PC em Modo Normal.

* Depois de alguns dias, se o seu computador estiver funcionando normalmente sem estes arquivos que foram excluidos pelo Malwarebytes Anti-malware, abra (execute) o Malwarebytes Anti-malware, clique na aba: Quarentena e clique no botão: Remover tudo.

*Execute novamente o programa Malwarebytes Anti-malware e clique na aba “Logs”, dê um duplo clique com o mouse sobre o log mais recente, selecione o log completo e copie-o.

 

Poste este log gerado pelo Malwarebytes Anti-Malware juntamente com um novo log do Hijackthis na sua próxima resposta e nos diga como está o seu computador depois de seguir este procedimento acima.

 

Ficamos no aguardo de sua resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

A janelinha ainda continua infelizmente aparecendo !

Mas aqui estão os logs:

 

log do Malwarebytes Anti-Malware:

 

Malwarebytes' Anti-Malware 1.38

Versão do banco de dados: 2340

Windows 5.1.2600 Service Pack 2

 

26/6/2009 20:52:37

mbam-log-2009-06-26 (20-52-37).txt

 

Tipo de Verificação: Completa (C:\|G:\|)

Objetos verificados: 271665

Tempo decorrido: 1 hour(s), 16 minute(s), 33 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 3

Valores do Registro infectados: 0

Ítens do Registro infectados: 2

Pastas infectadas: 8

Arquivos infectados: 3

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

HKEY_LOCAL_MACHINE\SOFTWARE\Miracle (Rogue.PerfectOptimizer) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\.pox (Rogue.FixTool) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\pofile (Rogue.FixTool) -> Quarantined and deleted successfully.

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

 

Pastas infectadas:

C:\Arquivos de programas\Perfect Optimizer (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

c:\arquivos de programas\perfect optimizer\Backup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

c:\arquivos de programas\perfect optimizer\Backup\Registry (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

c:\arquivos de programas\perfect optimizer\Backup\Registry\FirstBackup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

c:\arquivos de programas\perfect optimizer\Backup\Registry\FullBackup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

c:\arquivos de programas\perfect optimizer\Backup\Service (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

c:\arquivos de programas\perfect optimizer\Backup\Application (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

c:\arquivos de programas\perfect optimizer\Temp (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

 

Arquivos infectados:

c:\system volume information\_restore{c2768274-003b-4719-a76c-5e22b1965b5a}\RP775\A0113213.exe (Rogue.PerfectOptimizer) -> Quarantined and deleted successfully.

g:\system volume information\_restore{c2768274-003b-4719-a76c-5e22b1965b5a}\RP753\A0109759.exe (Rogue.Installer) -> Quarantined and deleted successfully.

c:\arquivos de programas\perfect optimizer\PerfectOptimizer.ini (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

 

 

e o novo log do HijackThis:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 00:30:44, on 27/6/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe

G:\opera.exe

C:\Documents and Settings\administrator\Desktop\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll

O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe"

O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: windows_system_32-dll.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -

O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - (no file)

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - (no file)

O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

 

--

End of file - 7966 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

:thumbsup: Mais 16 problemas foram removidos pelo Malwarebytes.

 

:seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

- Faça o download do SmitfraudFix.

 

Desabilite temporariamente seu anti vírus. Extraia os arquivos para o seu desktop (área de trabalho).

 

Reinicie o computador apertando intermitentemente F8 (ou a tecla F5 em alguns computares) e escolha modo seguro (ou modo de segurança).

 

* Se não possível executar o computador em Modo Seguro, faça o escaneamento no modo normal.

 

Entre na pasta criada pelo Smitfraudfix e dê um duplo-clique em Smitfraudfix. Pressione qualquer tecla para iniciá-lo.

 

Selecione a opção 2 e tecle enter. Ao perguntar se quer limpar o Registro, dê o Sim ( y ).

 

Reinicie o computador em modo normal e ative novamente a proteção do seu antivírus.

_____________________________________________________________________________

 

:seta: Siga também, por gentileza, as dicas deste tutorial para fazer um escaneamento de seu PC pelo Nod32 Online:

 

Tutorial do antivirus Nod32 Online

 

Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador:

C:\Arquivos de programas\EsetOnlineScanner\log

 

Na sua próxima resposta poste este log do Nod32 Online juntamente com o log do SmitFraudFix (rapport.txt ), que se encontrará em C:\ e também um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir estes procedimentos.

 

Ficamos no aguardo de sua resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ainda continua aparecendo a janela Autolt Error infelizmente :unsure: foto:http://img10.imageshack.us/img10/9438/imagemuem.jpg

Como dito, essa janela só aparece ao iniciar o pc, mas eu percebi que o pc fica um pouco lento até aparecer essa janela, mas depois de clicar no Ok o pc volta ao normal :thumbsup:

Mas aqui estão os logs:

 

log do Nod32 Online:

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=6

# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)

# OnlineScanner.ocx=1.0.0.5863

# api_version=3.0.2

# EOSSerial=008f4a627e4d024db63c1c5c9699d812

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2009-06-27 11:56:52

# local_time=2009-06-27 08:56:52 (-0300, Hora oficial do Brasil)

# country="Brazil"

# lang=1033

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=1797 37 100 100 936403281250

# scanned=176997

# found=2

# cleaned=2

C:\System Volume Information\_restore{C2768274-003B-4719-A76C-5E22B1965B5A}\RP760\A0111206.exe Win32/Toolbar.AskSBar application deleted - quarantined

G:\aopsfjafjoslsfl\Atalhos não utilizados da área de trabalho\TubeHunterUltra_v2.1.rar probably a variant of Win32/Agent trojan deleted - quarantined

# scan_time=11965

 

log do SmitFraudFix:

 

SmitFraudFix v2.423

 

Scan done at 13:13:45,82, dom 28/06/2009

Run from C:\Documents and Settings\administrator\Desktop\SmitfraudFix

OS: Microsoft Windows XP [versÆo 5.1.2600] - Windows_NT

The filesystem type is NTFS

Fix run in safe mode

 

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix

!!!Attention, following keys are not inevitably infected!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

»»»»»»»»»»»»»»»»»»»»»»»» Killing process

 

 

»»»»»»»»»»»»»»»»»»»»»»»» hosts

 

127.0.0.1 localhost

 

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

 

VACFix

Credits: Malware Analysis & Diagnostic

Code: S!Ri

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

 

S!Ri's WS2Fix: LSP not Found.

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

 

GenericRenosFix by S!Ri

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

 

 

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

 

IEDFix

Credits: Malware Analysis & Diagnostic

Code: S!Ri

 

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

 

Agent.OMZ.Fix

Credits: Malware Analysis & Diagnostic

Code: S!Ri

 

 

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

 

404Fix

Credits: Malware Analysis & Diagnostic

Code: S!Ri

 

 

»»»»»»»»»»»»»»»»»»»»»»»» RK

 

 

»»»»»»»»»»»»»»»»»»»»»»»» DNS

 

HKLM\SYSTEM\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{04C3A1DA-9070-4182-B453-44BD34AA1D0F}: DhcpNameServer=192.168.254.254

HKLM\SYSTEM\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{322A6189-5179-47E3-952F-CA74B8365A63}: DhcpNameServer=192.168.254.254

HKLM\SYSTEM\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{B9715597-1E02-47C5-91AE-8A27AB2DF780}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{04C3A1DA-9070-4182-B453-44BD34AA1D0F}: DhcpNameServer=192.168.254.254

HKLM\SYSTEM\CS1\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{322A6189-5179-47E3-952F-CA74B8365A63}: DhcpNameServer=192.168.254.254

HKLM\SYSTEM\CS1\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{B9715597-1E02-47C5-91AE-8A27AB2DF780}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS1\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{04C3A1DA-9070-4182-B453-44BD34AA1D0F}: DhcpNameServer=192.168.254.254

HKLM\SYSTEM\CS2\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{322A6189-5179-47E3-952F-CA74B8365A63}: DhcpNameServer=192.168.254.254

HKLM\SYSTEM\CS2\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{B9715597-1E02-47C5-91AE-8A27AB2DF780}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: DhcpNameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CS2\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer=208.67.220.220,208.67.222.222

HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.254.254

HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.254.254

HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.254.254

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System

!!!Attention, following keys are not inevitably infected!!!

 

"System"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» RK.2

 

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

 

Registry Cleaning done.

 

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix

!!!Attention, following keys are not inevitably infected!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

 

»»»»»»»»»»»»»»»»»»»»»»»» End

 

 

e o novo log do HijackThis:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:26:48, on 28/6/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\administrator\Desktop\HijackThis.exe

 

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll

O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe"

O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: windows_system_32-dll.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -

O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - (no file)

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - (no file)

O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

 

--

End of file - 7724 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

:seta: Abra o HijackThis, clique em Do a system scan only, marque a entrada abaixo e clique em Fix checked:

 

O4 - Global Startup: windows_system_32-dll.exe

____________________________________________________________________________

 

:seta: Vá no menu: Iniciar > Executar e digite:

 

services.msc

 

Tecle Enter.

 

Ache esse Serviço: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o., dê um duplo clique sobre ele com o botão esquerdo do mouse e escolha a opção: Desativado. Clique também em Parar e troque o Tipo de Inicialização para Desativado.

 

Repita este mesmo procedimento acima para desativar também estes outros dois serviços abaixo:

 

AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o.

 

Bonjour Service - Apple Inc.

____________________________________________________________________________

 

:seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

Reinicie o PC em entre em Modo Seguro (Fique apertando intermitentemente a tecla F8, ou a tecla F5 em alguns computadores, até que apareça uma tela preta em DOS e escolha a opção: Modo Seguro).

 

* Estando no modo seguro, abra o HijackThis e clique no botão Open the Misc Tools section e depois em Delete an NT service.

 

Digite isto:

 

mDNSResponder

 

Clique em Ok.

 

* clique novamente no botão Open the Misc Tools section e depois em Delete an NT service.

 

Digite isto:

 

Avg7UpdSvc

 

Clique em Ok.

 

* clique novamente no botão Open the Misc Tools section e depois em Delete an NT service.

 

Digite isto:

 

AVGEMS

 

Clique em Ok.

 

Reinicie o computador em Modo Normal.

 

* Vá no menu: Iniciar > Todos os programas > Acessórios > Windows Explorer > Localize esta pasta em destaque abaixo e a exclua:

 

C:\Arquivos de programas\Bonjour

____________________________________________________________________________

 

:seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

Faça o download do SDFix:

http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

 

Salve-o em sua Área de Trabalho (desktop).

 

Dê um duplo clique no SDFix.exe e a Ferramenta será instalada geralmente em C:\SDFix

 

Reinicie o computador em Modo Seguro (pressione a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização) e selecione a opção de Modo Seguro ou Modo de Segurança;

 

Entre na pasta SDFix que foi instalada no seu computador e dê um duplo clique no arquivo RunThis.bat

 

Tecle Y para que a Ferramenta inicie o processo de remoção.

 

Quando tudo terminar, você verá um aviso dizendo para apertar qualquer tecla para continuar.

 

Ao pressionar qualquer tecla, o computador será reiniciado automaticamente.

 

Após reiniciar, a Ferramenta ainda será executada novamente e irá terminar o seu trabalho, e ao surgir "The FixTool has finished", pressione qualquer tecla, uma janela com o Relatório do SDFix irá aparecer.

 

Caso você tenha fechado a janela, uma cópia do Relatório estará na pasta SDFix com o nome Report.txt.

 

Poste este relatório do SDFix na sua próxima resposta juntamente com um novo log do Hijackthis e nos diga como está o seu computador depois de seguir estes procedimentos. Ficamos no aguardo.

 

Depois de usar o SDFix, delete a ferramenta SDFix e a pasta C:\SDFix.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Finalmente deu certo ! :clap:

A janelinha não abriu mais ao iniciar o pc!

Acho que agora está tudo bem no pc

 

E aí estão os logs:

 

log do SDFix:

 

 

SDFix: Version 1.240

Run by Administrador on dom 28/06/2009 at 22:58

 

Microsoft Windows XP [versÆo 5.1.2600]

Running From: C:\SDFix

 

Checking Services :

 

 

Restoring Default Security Values

Restoring Default Hosts File

 

Rebooting

 

 

Checking Files :

 

No Trojan Files Found

 

 

 

 

 

 

Removing Temp Files

 

ADS Check :

 

 

 

Final Check :

 

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-06-28 23:12:02

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

scanning hidden processes ...

 

scanning hidden services ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAI3KP09.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA7ESNZ1.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAI381CL.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAI3C5CP.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAFUWBFD.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAEJ4ROT.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CACPAPTI.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA5007LX.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAOLALDA.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA3M8R7T.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAOP2XPQ.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA63WLMN.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA8L6VOL.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA2FUJI9.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAU7G1E3.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA18G7TP.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CAOLELVW.xml 32768 bytes

C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\AHU3KXA7\CA6389A7.xml 32768 bytes

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 18

 

 

Remaining Services :

 

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"="C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"

"C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"="C:\\Arquivos de programas\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

"C:\\Arquivos de programas\\K-Lite\\eMule\\emule.exe"="C:\\Arquivos de programas\\K-Lite\\eMule\\emule.exe:*:Enabled:eMule"

"C:\\Arquivos de programas\\uTorrent\\utorrent.exe"="C:\\Arquivos de programas\\uTorrent\\utorrent.exe:*:Enabled:æTorrent"

"C:\\Arquivos de programas\\Mozilla Firefox\\FIREFOX.EXE"="C:\\Arquivos de programas\\Mozilla Firefox\\FIREFOX.EXE:*:Enabled:Firefox"

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\\Arquivos de programas\\Opera\\Opera.exe"="C:\\Arquivos de programas\\Opera\\Opera.exe:*:Enabled:Opera Internet Browser"

"C:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe"="C:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe:*:Enabled:VideoAcceleratorService"

"G:\\opera.exe"="G:\\opera.exe:*:Enabled:Opera Internet Browser"

"C:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAccelerator.exe"="C:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAccelerator.exe:*:Enabled:VideoAccelerator"

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"="C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"

"C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"="C:\\Arquivos de programas\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

 

Remaining Files :

 

 

 

Files with Hidden Attributes :

 

Wed 5 May 1999 95,698 ..SH. --- "C:\COMMAND.COM"

Sun 8 Aug 2004 1,676 ..SHR --- "C:\MSDOS.BAK"

Sun 8 Aug 2004 53,248 ...H. --- "C:\Arquivos de programas\Acess¢rios\mspcx32.dll"

Mon 26 Jan 2009 1,740,632 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\SDUpdate.exe"

Mon 26 Jan 2009 5,365,592 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\SpybotSD.exe"

Mon 26 Jan 2009 2,144,088 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe"

Sun 5 Dec 2004 56 ..SHR --- "C:\WINDOWS\system32\4525EC329C.sys"

Wed 22 Jun 2005 45,568 A.SHR --- "C:\program files\Replay Converter\cygz.dll"

Fri 14 Jan 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.key.bak"

Sat 14 Jan 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"

Wed 5 Dec 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"

Sun 13 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv03.tmp"

Sun 6 Mar 2005 20 A..H. --- "C:\Documents and Settings\administrator\Meus documentos\Minhas m£sicas\Backup de Licen‡a\drmv1lic.bak"

Fri 14 Jan 2005 4,348 ...H. --- "C:\Documents and Settings\administrator\Meus documentos\Minhas m£sicas\Backup de Licen‡a\drmv1key.bak"

Sat 5 Mar 2005 400 A.SH. --- "C:\Documents and Settings\administrator\Meus documentos\Minhas m£sicas\Backup de Licen‡a\drmv2key.bak"

Wed 25 Jan 2006 53,318 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\CF_BalletMirror.zip"

Wed 25 Jan 2006 43,092 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\CF_MartialArtsMat.zip"

Wed 25 Jan 2006 103,683 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_pinkolympicdivingboard.zip"

Wed 25 Jan 2006 42,260 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bouncentrim.zip"

Wed 25 Jan 2006 44,112 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_grasshandstandv2.zip"

Wed 25 Jan 2006 33,334 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_gymtile01.zip"

Wed 25 Jan 2006 31,514 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_gymtile02.zip"

Wed 25 Jan 2006 57,457 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_gymtile03.zip"

Wed 25 Jan 2006 66,159 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_gymtile04.zip"

Wed 25 Jan 2006 24,417 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_dancestationmodela1fm.zip"

Wed 25 Jan 2006 117,808 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf-slimlineliloblue.zip"

Wed 25 Jan 2006 61,265 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_toolroll.ZIP"

Wed 25 Jan 2006 34,696 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_magicbroomstick.zip"

Wed 25 Jan 2006 320,617 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_forgerseasel.zip"

Wed 25 Jan 2006 2,335,303 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_betterbaby.ZIP"

Wed 25 Jan 2006 45,249 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_animated_7dsmoviecamera.zip"

Wed 25 Jan 2006 715,430 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bedtuckin05.zip"

Wed 25 Jan 2006 473,268 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bedtuckin01.zip"

Wed 25 Jan 2006 701,382 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bedtuckin03.zip"

Wed 25 Jan 2006 476,211 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bedtuckin02.zip"

Wed 25 Jan 2006 771,097 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cf_bedtuckin04.zip"

Wed 25 Jan 2006 20,215 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\cfcrystalball4two.zip"

Wed 25 Jan 2006 23,328 A..H. --- "C:\@Arquivos Kazaa.com.br\Atalhos nÆo utilizados da  rea de trabalhoa\Paulo\Siemens\asfddadadadadas\ddssd\Stareoutscrn.zip"

 

Finished!

 

 

e o novo log do HijackThis :

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 00:26:39, on 29/6/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\administrator\Desktop\HijackThis.exe

 

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll

O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O4 - HKLM\..\Run: [speedBitVideoAccelerator] "C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe"

O4 - HKLM\..\Run: [Ad-Watch] C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -

O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

 

--

End of file - 7340 bytes

 

 

Você recomenda que eu faça ainda algo mais no pc ?

E se esse problema voltar ou outro mesmo aparecer eu venho aqui pedir a sua ajuda hehehehe

Mas de qualquer jeito muito obrigado Antonio por toda a sua ajuda e também paciência ! hehehehe :joia:

Valeu

Compartilhar este post


Link para o post
Compartilhar em outros sites
Finalmente deu certo !

A janelinha não abriu mais ao iniciar o pc!

Acho que agora está tudo bem no pc

:thumbsup: Ficamos felizes que o problema foi resolvido.

 

:seta: Baixe o programa Avenger no link abaixo e extraia o conteúdo para o desktop (área de trabalho):

http://swandog46.geekstogo.com/avenger2/download.php

 

*Selecione e copie (Ctrl+C) todo o texto dentro do CODE (caixa branca) abaixo:

 

Files to delete:c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\windows_system_32-dll.exe

 

*Execute o programa Avenger

*Clique em [Load Script] > [Paste from Clipboard]

*Clique em [Execute] > [OK]

*O PC será reiniciado

*O relatório será criado em C:\avenger.txt

_____________________________________________________________________________

 

:seta: Instale estes programas e use-os agora e semanalmente para fazer uma limpeza do seu PC e para deixá-lo mais eficiente e otimizado:

 

MV RegClean

 

MV AntiSpy

 

SpywareBlaster

 

_____________________________________________________________________________

 

:seta: Para evitar que os virus voltem, desative e ative novamente a restauração do sistema. Para isso, vá no menu: Iniciar - Painel de Controle - Sistema - Clique na aba: Restauração do Sistema - Marque a caixinha: Desativar restauração do sistema - Clique no botão: Aplicar e no botão: Ok.

 

Depois disso, volte no mesmo local: Iniciar - Painel de Controle - Sistema - Clique na aba: Restauração do Sistema - Desmarque a caixinha: Desativar restauração do sistema - Clique no botão: Aplicar e no botão: Ok.

_____________________________________________________________________________

 

:seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

Baixe > JavaRa

 

Descompacte-o e dê um duplo-clique no JavaRa.exe. Selecione a língua inglesa (English) ou outro idioma de sua preferência e clique no botão Select. Depois clique em Search For Updates. Selecione a opção Update Using jucheck.exe. Clique então no botão Search.

 

Se o Java estiver atualizado em seu PC, você receberá um aviso de que tem a última versão. Caso contrário, aguarde a nova versão do Java ser baixada e instalada. Feche temporariamente os seus navegadores (Internet Explorer, Firefox, etc). Depois clique no botão Remove Older Versions, confirme clicando no botão Sim e clique em Ok e clique em Ok novamente para que as versões antigas do Java que existirem no PC sejam desinstaladas.

_____________________________________________________________________________

 

:seta: Se o seu Windows for original, baixe e instale o Service Pack 3:

http://superdownloads.uol.com.br/download/...s-service-pack/

_____________________________________________________________________________

 

:seta: Depois de seguir as dicas acima poste um o log do Avenger que estará em C:\avenger.txt juntamente com um novo log do Hijackthis e nos diga como está o seu PC depois disto.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

O meu Windows não é original, mas vou tentar instalar o SP3 quando terminar de baixar, pois a minha conexão é muito lenta

E aqui estão os logs:

 

log do Avenger:

 

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

 

Platform: Windows XP

 

*******************

 

Script file opened successfully.

Script file read successfully.

 

Backups directory opened successfully at C:\Avenger

 

*******************

 

Beginning to process script file:

 

Rootkit scan active.

No rootkits found!

 

 

Error: "c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\" is a folder, not a file!

Deletion of file "c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\" failed!

Status: 0xc00000ba (STATUS_FILE_IS_A_DIRECTORY)

--> use "Folders to delete:" instead of "Files to delete:" to delete a directory

 

 

Error: file "windows_system_32-dll.exe" not found!

Deletion of file "windows_system_32-dll.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

 

 

Completed script processing.

 

*******************

 

Finished! Terminate.

 

e o novo log do HijackThis:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:32:07, on 29/6/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

G:\opera.exe

C:\Documents and Settings\administrator\Desktop\programas e coisas que resolveram o Autolt Error\HijackThis.exe

 

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.3000.1001\pt-br\msntb.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Arquivos de programas\Google\Web Accelerator\GoogleWebAccToolbar.dll

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: shorten url - http://www.cjb.net/menuext.html

O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {CC5C7FFD-E058-4390-A22A-FD08CCD9A3CE} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{0416794C-9083-4544-8163-0CFA90D1BAAB}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{04F3740A-F11D-4900-B82A-564CCB9D4053}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{3B3C09CE-5A49-4085-B8ED-C0ECD2F690BE}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{7862CE84-3DED-42EE-9750-CDA60936645C}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{A0CB817D-AD60-4906-ACEC-72A8597BEA66}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9F9753-48FF-4E38-A888-5DA40DBCFEA4}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB4F3FA-81B0-490D-BC7D-E2F663E9B67F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{DF4FB8F8-F5B4-4EE6-B169-A7CB090B75E0}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{E51DCA47-FE65-4BF2-9868-5777F46E8306}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\..\{01EBD1BD-D540-44FD-9A92-A33BB92BDC7F}: NameServer = 208.67.220.220,208.67.222.222

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

 

--

End of file - 7172 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

:!: Você não copiou completamente o texto dentro do CODE e por este motivo o procedimento com o Avenger falhou.

 

Exclua o log do Avenger que está em C:\avenger.txt

 

*Selecione e copie (Ctrl+C) todo o texto dentro do CODE (caixa branca) abaixo:

 

Files to delete:c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\windows_system_32-dll.exe

 

*Execute o programa Avenger

*Clique em [Load Script] > [Paste from Clipboard]

*Clique em [Execute] > [OK]

*O PC será reiniciado

*Poste o novo relatório que será criado em C:\avenger.txt na sua próxima resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Eu copiei certo cara

Também estranhei quando o log do Avenger disse que não encontrou o windows_system_32-dll.exe

Tentei fazer de novo e deu na mesma coisa, windows_system_32-dll.exe not found

Mas não foi esta entrada que você pediu para marcar e clicar em Fix checked no HijackThis ? Acho que essa entrada windows_system_32-dll.exe já foi deletada

Tenho até o backup aqui!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Eu copiei certo cara

Também estranhei quando ele disse que não encontrou o windows_system_32-dll.exe

Mas não foi esta entrada que você pediu para marcar e clicar em Fix checked no HijackThis ? Acho que essa entrada windows_system_32-dll.exe já foi deletada

Tenho até o backup aqui!

 

:) disse isto porque no seu log do Avenger está constando assim:

 

Error: "c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\" is a folder, not a file!

 

Isto indica que você copiou de C:\ até Inicializar. Mas o certo seria copiar de C:\ até windows_system_32-dll.exe, ficando então assim o texto a ser inserido no Avenger:

 

Files to delete:

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\windows_system_32-dll.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

De fato esqueci de botar completo

Mas acabei de fazer de novo do jeito certo e ainda o Avenger não encontra o windows_system_32-dll.exe

Acho que já foi deletada mesmo

 

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

 

Platform: Windows XP

 

*******************

 

Script file opened successfully.

Script file read successfully.

 

Backups directory opened successfully at C:\Avenger

 

*******************

 

Beginning to process script file:

 

Rootkit scan active.

No rootkits found!

 

 

Error: file "c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\windows_system_32-dll.exe" not found!

Deletion of file "c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\windows_system_32-dll.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

 

 

Completed script processing.

 

*******************

 

Finished! Terminate.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Agora está tudo certo, realmente ele já não existe.

 

:seta: Baixe o programa ToolsCleaner:

http://pc-system.fr/TC/ToolsCleaner2.exe

Salve-o no Desktop (área de trabalho);

Feche programas que estejam abertos e execute a ferramenta.

Clique no botão Recherche para iniciar o scan. <-- Aguarde!

Terminando, teremos relacionados os itens que serão removidos.

Clique no botão Supression para remover os itens encontrados.

Clique, à seguir, em Quitter.

_____________________________________________________________________________

 

:seta: Para evitar que os virus voltem, desative e ative novamente a restauração do sistema. Para isso, vá no menu: Iniciar - Painel de Controle - Sistema - Clique na aba: Restauração do Sistema - Marque a caixinha: Desativar restauração do sistema - Clique no botão: Aplicar e no botão: Ok.

 

Depois disso, volte no mesmo local: Iniciar - Painel de Controle - Sistema - Clique na aba: Restauração do Sistema - Desmarque a caixinha: Desativar restauração do sistema - Clique no botão: Aplicar e no botão: Ok.

_____________________________________________________________________________

 

:thumbsup: Foi um prazer ajudar, conte sempre conosco!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Só uma última dúvida, é realmente necessário e recomendável usar o ToolsCleaner ?

É que ele remove todos os programas usados neste tópico, mas eu queria guardá-los no caso de precisar no futuro !

Compartilhar este post


Link para o post
Compartilhar em outros sites
Só uma última dúvida, é realmente necessário e recomendável usar o ToolsCleaner ?

É que ele remove todos os programas usados neste tópico, mas eu queria guardá-los no caso de precisar no futuro !

Se você quizer deixar os programas usados aí no seu PC você pode deixá-los. Mas há alguns programas como o Combofix, o Avenger e outros que ficarão desatualizados e aí já não serão muito úteis. No caso do Combofix por exemplo o ideal é baixá-lo e utilizá-lo no momento que você precisa (para baixar a versão mais nova dele).

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.