Jump to content

Ganhe $$$ escrevendo tutoriais para nós!


Foto

analise de log

malware




  • Faça login para responder
13 respostas neste tópico

#1 Caverna_br

Caverna_br
  • Participante
  • 64 mensagens

Publicado 09 June 2012 - 09:26 PM

ja fiz os procedimentos.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:17:23, on 09/06/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Users\DV5-2115br\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
G:\programas\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/3
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/3
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [BankerFixV3] \LinhaDefensiva\rotinas\postreboot.bat
O4 - HKLM\..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe
O4 - HKLM\..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\DV5-2115br\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [Google Update] "C:\Users\DV5-2115br\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Facebook Messenger.lnk = DV5-2115br\AppData\Local\Facebook\Messenger\2.1.4520.0\FacebookMessenger.exe
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: www.bancobrasil.com.br
O15 - Trusted Zone: www14.bancobrasil.com.br
O15 - Trusted Zone: www2.bancobrasil.com.br
O15 - Trusted Zone: www.bb.com.br
O15 - Trusted Zone: www.universalmusic.com
O15 - Trusted Zone: http://www.universalmusicplatform.com
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: GbPluginBb - C:\Program Files (x86)\GbPlugin\gbieh.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Pimsgss (cics.region2) - Unknown owner - \\.\globalrootC:\Windows\system32\svchost.exe (file missing)
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Gbp Service (GbpSv) - - C:\PROGRA~2\GbPlugin\GbpSv.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Unknown owner - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PEVSystemStart - Unknown owner - C:\32788R22FWJFW\pev.3XE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Tfsnudfa (siside) - Unknown owner - \\.\globalrootC:\Windows\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10102 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12133 bytes




#2 Mr.Million

Mr.Million

    Consumer Security MVP

  • Especialista
  • 59595 mensagens

Publicado 09 June 2012 - 09:58 PM

Download o Kaspersky Virus Removal Tool.

Você será conduzido a uma página da Kaspersky, solicitando um email para cadastro, nome e sobrenome. Somente o campo "email" é obrigatório.
Informe seu email depois clique no botão Submit Form.
A página será recarregada. Clique no botão Download

Salve-o em sua Área de trabalho.

Duplo clique no arquivo "setup" e aguarde a instalação;
Na próxima tela marque I accept the licence agreement e clique em Start

Clique no botão Posted Image e marque:
  • Meu Computador
  • Disco local (C:) (a letra do disco local pode variar)
Clique em Actions e marque os dois quadros ( se já não estiverem marcados):


Posted Image
- Clique na aba Automatic Scan e aguarde o término da verificação.

- Clique no botão Posted Image, em Detected threats e no botão "Save".
- Copie o conteúdo do arquivo salvo (se houver algo detectado) e poste na sua próxima resposta.
Posted Image

#3 Mr.Million

Mr.Million

    Consumer Security MVP

  • Especialista
  • 59595 mensagens

Publicado 10 June 2012 - 03:46 PM

Aguardando....
Posted Image

#4 Caverna_br

Caverna_br
  • Participante
  • 64 mensagens

Publicado 11 June 2012 - 02:54 AM

Status: Will be quarantined on system restart (events: 6)
10/06/2012 18:32:08 Will be quarantined on system restart Trojan program HEUR:Backdoor.Win32.Generic C:\Windows\assembly\GAC_32\Desktop.ini High
10/06/2012 18:32:27 Will be quarantined on system restart Trojan program HEUR:Backdoor.Win64.Generic C:\Windows\assembly\GAC_64\Desktop.ini High
11/06/2012 00:44:39 Will be quarantined on system restart Trojan program HEUR:Backdoor.Win32.Generic C:\Windows\assembly\GAC_32\ High
11/06/2012 00:45:31 Will be quarantined on system restart Trojan program HEUR:Backdoor.Win64.Generic C:\Windows\assembly\GAC_64\ High
11/06/2012 00:49:19 Will be quarantined on system restart Trojan program HEUR:Backdoor.Win32.Generic c:\Windows\assembly\GAC_32\Desktop.ini High
11/06/2012 00:49:56 Will be quarantined on system restart Trojan program HEUR:Backdoor.Win64.Generic c:\Windows\assembly\GAC_64\Desktop.ini High
Status: Will be deleted when the computer is restarted (events: 61)
10/06/2012 18:43:49 Will be deleted when the computer is restarted Trojan program Trojan-Downloader.Win32.Agent.gyal C:\Windows\assembly\tmp\U\000000cf.@ High
10/06/2012 19:02:07 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\adihdaudaddservice.dll High
10/06/2012 19:02:18 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\Afc.dll High
10/06/2012 19:02:27 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\Alpham1.dll High
10/06/2012 19:02:33 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\atitool.dll High
10/06/2012 19:02:39 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\AVerBDA.dll High
10/06/2012 19:02:46 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\backupclientsvc.dll High
10/06/2012 19:02:59 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\bcserver.dll High
10/06/2012 19:03:04 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\bc_ngn.dll High
10/06/2012 19:03:19 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\bdselfpr.dll High
10/06/2012 19:05:00 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\bh611.dll High
10/06/2012 19:08:12 Will be deleted when the computer is restarted Trojan program Backdoor.Win64.ZAccess.av C:\Windows\System32\consrv.dll High
10/06/2012 19:08:13 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\contentfilter.dll High
10/06/2012 19:08:12 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\co_mon.dll High
10/06/2012 19:08:54 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\db2.dll High
10/06/2012 19:09:01 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\DcCam.dll High
10/06/2012 19:09:15 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\epfwtdi.dll High
10/06/2012 19:09:21 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\EPSON_EB_RPCV4_01.dll High
10/06/2012 19:09:29 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\flpydisk.dll High
10/06/2012 19:09:39 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\gdrv.dll High
10/06/2012 19:09:50 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\gv3.dll High
10/06/2012 19:09:57 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\icepack.dll High
10/06/2012 19:10:35 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\inetaccs.dll High
10/06/2012 19:10:43 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\IPSECSHM.dll High
10/06/2012 19:10:49 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\irsir.dll High
10/06/2012 19:11:00 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\kl1.dll High
10/06/2012 19:11:14 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\knobserv.dll High
10/06/2012 19:11:19 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\lexbces.dll High
10/06/2012 19:11:25 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\LVPrcMon.dll High
10/06/2012 19:11:34 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\M3AD.dll High
10/06/2012 19:12:17 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\mouhid.dll High
10/06/2012 19:12:40 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\Mtlstrm.dll High
10/06/2012 19:13:04 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\ngserver.dll High
10/06/2012 19:13:13 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\nmraapache.dll High
10/06/2012 19:13:19 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\ohci1394.dll High
10/06/2012 19:13:52 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\ooclevercacheagent.dll High
10/06/2012 19:14:01 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\palmusbd.dll High
10/06/2012 19:17:04 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\pavdrv.dll High
10/06/2012 19:17:04 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\pepifilter.dll High
10/06/2012 19:17:04 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\procexp111.dll High
10/06/2012 19:17:49 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\prtg4service.dll High
10/06/2012 19:17:54 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\psdistributionagent.dll High
10/06/2012 19:18:01 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\ql12160.dll High
10/06/2012 19:18:10 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\se44nd5.dll High
10/06/2012 19:18:15 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\SE2Dmgmt.dll High
10/06/2012 19:18:24 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\SerTVOutCtlr.dll High
10/06/2012 19:18:33 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\smservaz.dll High
10/06/2012 19:18:40 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\smsmdd.dll High
10/06/2012 19:18:48 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\SrvcTPIOMngr.dll High
10/06/2012 19:18:55 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\swwd.dll High
10/06/2012 19:19:31 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\tangoservice.dll High
10/06/2012 19:19:46 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\tcpip.dll High
10/06/2012 19:19:36 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\tifm21.dll High
10/06/2012 19:19:59 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\tmmbd.dll High
10/06/2012 19:20:07 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\transarcafsdaemon.dll High
10/06/2012 19:20:16 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\vwd.dll High
10/06/2012 19:20:32 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\w810mdm.dll High
10/06/2012 19:21:14 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\WinHttpAutoProxySvc.dll High
10/06/2012 19:21:28 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\winpppoverethernet.dll High
10/06/2012 19:21:20 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\winvnc4.dll High
10/06/2012 19:22:05 Will be deleted when the computer is restarted Trojan program Trojan.Win32.Genome.aezhy C:\Windows\System32\XUIF.dll High

#5 Mr.Million

Mr.Million

    Consumer Security MVP

  • Especialista
  • 59595 mensagens

Publicado 11 June 2012 - 10:31 AM

Desabilite o seu Antivírus, AntiSpyware e Firewall para não haver conflitos. Mantenha-os desativados até terminar as instruções.

Download ComboFix

Salve no seu Desktop ( Para que a Ferramenta seja executada corretamente é necessário que esteja no Desktop (Área de trabalho)
Feche todas as janelas e programas.


É necessário estar conectado durante o procedimento com o ComboFix;

Execute o combofix.exe, tecle "Sim" para prosseguir. Aguarde, pois é um pouco demorado.

OBS: Caso não queira que seja instalado o Console de Recuperação do Windows, clique em "Não" e depois concorde para que a verificação prossiga.
Ao ser instalado o Console, na Inicialização do Sistema será apresentada a tela para Seleção dos Sistemas Operacionais.
Mais informações sobre o Console:
http://support.microsoft.com/kb/307654/pt-br

O ComboFix reiniciará o PC automaticamente para completar o processo de remoção. Caso isso não aconteça, reinicie manualmente.
Quando acabar, será gerado um Log, que estará em C:\ComboFix.txt. Selecione, copie e cole o conteúdo do ComboFix.txt na sua próxima resposta + um novo Log do HijackThis .


IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando. Para parar ou sair do ComboFix, tecle "N".

OBS 2: Não execute o ComboFix mais do que uma vez. Isso irá sobreescrever o Log e dificultará a remoção do(s) malware(s)

Caso ocorra algum erro, reinicie o computador em Modo Seguro (pressione a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização) e repita o procedimento.
Posted Image

#6 Caverna_br

Caverna_br
  • Participante
  • 64 mensagens

Publicado 11 June 2012 - 04:21 PM

o programa nao esta rodando esta parando qndo abre as pastas na instalação, e tentei entrar no modo seguro com rede nao completou. mas o OS abre normalmente.

Editado por Caverna_br, 11 June 2012 - 04:21 PM.
''


#7 Mr.Million

Mr.Million

    Consumer Security MVP

  • Especialista
  • 59595 mensagens

Publicado 11 June 2012 - 04:28 PM

Download:
Dr.Web CureIT

Salve- o no Desktop

Dê um duplo-clique em drweb-cureit.

Na janela que abrir, clique em Iniciar -- OK.

Será iniciada a "
Verificação rápida" - Feche a janela de propaganda!

Terminando,marque a caixa de "
Verificação Completa".

Clique em "Options" --> Em"Change settings",desmarque a "Heuristic analysis".

Clique em "Iniciar verificação" -- Aguarde!

Surgindo mensagens para mover ou desinfectar arquivos,clique em Sim para todos.

Terminando,clique em "
Ficheiro" --> "Guardar lista de relatórios".

Procure salvá-lo em Pasta de fácil localização, tipo Meus Documentos.- ( DrWeb.csv ) -- Texto!
Poste na sua próxima resposta: DrWeb.csv +um novo Log do HijackThis
Posted Image

#8 Caverna_br

Caverna_br
  • Participante
  • 64 mensagens

Publicado 12 June 2012 - 02:56 PM

nao to conseguindo nexaro arquivo drweb no modo seguro ele aparece, no modo normal nao, qndo clico pra anexar ele nao aparece na selecao de arquivo.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:34:31, on 12/06/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\DV5-2115br\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/3
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/3
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [BankerFixV3] \LinhaDefensiva\rotinas\postreboot.bat
O4 - HKLM\..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe
O4 - HKLM\..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\DV5-2115br\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [Google Update] "C:\Users\DV5-2115br\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Facebook Messenger.lnk = DV5-2115br\AppData\Local\Facebook\Messenger\2.1.4520.0\FacebookMessenger.exe
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: www.bancobrasil.com.br
O15 - Trusted Zone: www14.bancobrasil.com.br
O15 - Trusted Zone: www2.bancobrasil.com.br
O15 - Trusted Zone: www.bb.com.br
O15 - Trusted Zone: www.universalmusic.com
O15 - Trusted Zone: http://www.universalmusicplatform.com
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: GbPluginBb - C:\Program Files (x86)\GbPlugin\gbieh.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Pimsgss (cics.region2) - Unknown owner - \\.\globalrootC:\Windows\system32\svchost.exe (file missing)
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Gbp Service (GbpSv) - - C:\PROGRA~2\GbPlugin\GbpSv.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Unknown owner - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PEVSystemStart - Unknown owner - C:\32788R22FWJFW\pev.3XE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Tfsnudfa (siside) - Unknown owner - \\.\globalrootC:\Windows\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10102 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12063 bytes

Editado por Caverna_br, 12 June 2012 - 03:47 PM.
''


#9 Mr.Million

Mr.Million

    Consumer Security MVP

  • Especialista
  • 59595 mensagens

Publicado 12 June 2012 - 03:57 PM

Como está o PC ?
Posted Image

#10 Caverna_br

Caverna_br
  • Participante
  • 64 mensagens

Publicado 12 June 2012 - 04:41 PM

pareceque esta normal, mas as vezes qndo o windows carrega ele abre o desktop mas nao abre o resto das coisas tendo que reiniciar! so sei queo dr web acho uns 67 trheads worms backdoors!






Tópicos Relacionados Collapse

  Tópico Fórum Criado por Estatísticas Última atualização

Tópicos com palavra-chave: malware





Ganhe $$$ escrevendo tutoriais para nós!