Resultado do análise da Farbar Recovery Scan Tool (FRST) (x64) Versão: 11-12-2021 Executado por User (administrador) em ATAMULACA (Gigabyte Technology Co., Ltd. Z370M DS3H) (13-12-2021 21:41:14) Executando a partir de C:\Users\User\Desktop Perfis Carregados: User Plataforma: Microsoft Windows 10 Pro Versão 20H2 19042.1348 (X64) Idioma: Português (Brasil) Navegador padrão: Chrome Modo da Inicialização: Normal ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (ADLICE (ASCOET JULIEN) -> ) C:\Program Files\RogueKiller\RogueKiller64.exe (ADLICE (ASCOET JULIEN) -> ) C:\Program Files\RogueKiller\RogueKillerSvc.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\afwServ.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswEngSrv.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastSvc.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastUI.exe <4> (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <30> (Malwarebytes Inc -> Malwarebytes) D:\Arquivos e Downloads\adwcleaner_8.3.1.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_3.59.11001.0_x64__8wekyb3d8bbwe\gamingservices.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_3.59.11001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIC.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe (TunnelBear (McAfee Canada ULC) -> TunnelBear) D:\Arquivos e Downloads\TunnelBear\TunnelBear.Maintenance.exe ==================== Registro (Whitelisted) =================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [157464 2021-12-09] (Avast Software s.r.o. -> AVAST Software) HKLM-x32\...\Run: [IObit Malware Fighter] => D:\Arquivos e Downloads\IObit Malware Fighter\IMF.exe [6738896 2021-02-23] (IObit Information Technology -> IObit) [Arquivo não assinado] HKLM-x32\...\Run: [USB Gamepad] => C:\WINDOWS\USB Vibration\7906\USB Gamepad.exe [796784 2008-12-10] (Shen Zhen Dragon Rise Macro Technology Limited Company -> ) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5890504 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706344 2021-09-27] (Oracle America, Inc. -> Oracle Corporation) HKU\S-1-5-21-3341833902-1897029191-1718594085-1001\...\Run: [Overwolf] => D:\Arquivos e Downloads\Overwolf\OverwolfLauncher.exe [1807192 2021-11-23] (Overwolf Ltd -> Overwolf Ltd.) HKU\S-1-5-21-3341833902-1897029191-1718594085-1001\...\Run: [GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE] => "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 HKU\S-1-5-21-3341833902-1897029191-1718594085-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 HKLM\Software\Microsoft\Active Setup\Installed Components: [{1BED99F6-0143-9742-0100-04318AB5EC76}] -> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\96.0.4664.110\Installer\chrmstp.exe [2021-12-13] (Google LLC -> Google LLC) HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restrição <==== ATENÇÃO ==================== Tarefas Agendadas (Whitelisted) ============ (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) Task: {0020F9B6-5F08-441A-B699-BA0A2BE944C8} - System32\Tasks\Opera scheduled Autoupdate 1631937680 => C:\Users\User\AppData\Local\Programs\Opera\launcher.exe [42724048 2021-09-13] (Opera Software AS -> Opera Software) Task: {08B1D880-0222-4491-B873-EFC108446581} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-06-21] (Google LLC -> Google LLC) Task: {0B19186D-D82F-4ADF-8A64-C0A4957AC611} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-08-05] (NVIDIA Corporation -> NVIDIA Corporation) Task: {2755C47A-40DF-49DE-BBF2-4D6F0517675A} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1907712 2021-06-10] () [Arquivo não assinado] Task: {283ECEB0-4129-418E-AA10-AE421116D42A} - System32\Tasks\Uninstaller_SkipUac_User => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [6716952 2021-07-21] (IObit CO., LTD -> IObit) Task: {2F64A069-82E2-47FD-A268-92B448E0A391} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-08-05] (NVIDIA Corporation -> NVIDIA Corporation) Task: {32629E85-19ED-4632-BD37-E39C1BACA437} - System32\Tasks\R@1n-KMS\Office365ProPlus => wmic path SoftwareLicensingProduct where (ID="d450596f-894d-49e0-966a-fd39ed4c4c64") call Activate Task: {33694D9D-FFC6-4D60-BD2D-963B76C38755} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22799320 2021-12-02] (Microsoft Corporation -> Microsoft Corporation) Task: {3D47A673-812F-4443-8CDF-1FDDD9BDAC0C} - System32\Tasks\IMF_SkipUAC_User => D:\Arquivos e Downloads\IObit Malware Fighter\IMF.exe [6738896 2021-02-23] (IObit Information Technology -> IObit) [Arquivo não assinado] Task: {40EAA852-024B-4967-B183-FCB5DE37C9CB} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-08-05] (NVIDIA Corporation -> NVIDIA Corporation) Task: {4B7D1A51-27C1-4D22-B5F9-3C2AEF9A2BB6} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-08-05] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log Task: {4DAED166-2358-4610-8CAE-892A319E8532} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-08-05] (NVIDIA Corporation -> NVIDIA Corporation) Task: {4EEB8F55-694E-461D-8918-08F0492AF6F4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154456 2021-06-21] (Google LLC -> Google LLC) Task: {52802E1D-66EE-4533-8D41-5D79A1441486} - System32\Tasks\Opera GX scheduled Autoupdate 1624670633 => C:\Users\User\AppData\Local\Programs\Opera GX\launcher.exe [2201808 2021-11-24] (Opera Software AS -> Opera Software) Task: {54624F9F-1B34-4AD5-9D58-BFB42867DCB5} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339120 2021-08-05] (NVIDIA Corporation -> NVIDIA Corporation) Task: {54C1AE7B-6159-4CF3-B8F5-9D35BCE06EC1} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22799320 2021-12-02] (Microsoft Corporation -> Microsoft Corporation) Task: {5990A3D8-A05E-46EE-9236-F8A1EE31486E} - System32\Tasks\iTopVPN_Scheduler_User => D:\Arquivos e Downloads\iTop VPN\iTopVPN.exe [5672960 2021-07-02] (ORANGE VIEW LIMITED -> iTop Inc.) Task: {5CCDB9D9-F7DF-49E9-9AC0-FC0556423CAC} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-08-05] (NVIDIA Corporation -> NVIDIA Corporation) Task: {5D51A3BC-8B27-42B0-BB62-01EDAC1320A4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {5DB50625-207E-458E-B333-7F88F7308571} - System32\Tasks\iTopVPN_SkipUAC_User => D:\Arquivos e Downloads\iTop VPN\iTopVPN.exe [5672960 2021-07-02] (ORANGE VIEW LIMITED -> iTop Inc.) Task: {60C5AEF4-32F2-4272-B2BF-EB9F890D9462} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1626108598 => C:\Users\User\AppData\Local\Programs\Opera GX\launcher.exe [2201808 2021-11-24] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\User\AppData\Local\Programs\Opera GX\assistant" $(Arg0) Task: {61790DDD-2411-43FA-821D-0B091A9A317C} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-08-05] (NVIDIA Corporation -> NVIDIA Corporation) Task: {643DD83E-B1F3-4B89-A3C0-8BFF07D85C9F} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\Explorer.exe /NoUACCheck Task: {699A47FA-52F7-4E87-8A85-5954A5727A1C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1562376 2021-08-16] (Adobe Inc. -> Adobe Inc.) Task: {6A26F682-A5BE-45A2-A8C7-35C1980D7B99} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [139656 2021-12-09] (Microsoft Corporation -> Microsoft Corporation) Task: {744C440A-6400-4299-9B01-7E5AC4BDAEE3} - System32\Tasks\ASC_SkipUac_User => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe /SkipUac (Nenhum Arquivo) Task: {7E1EFE5D-C171-45EC-B38D-A00DD7BF153E} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-08-05] (NVIDIA Corporation -> NVIDIA Corporation) Task: {8EF3D300-D7F5-4359-B781-8B05B3511469} - System32\Tasks\ASC_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe /Task (Nenhum Arquivo) Task: {90B40C8B-D470-4997-8283-CB398C96BA4A} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [139656 2021-12-09] (Microsoft Corporation -> Microsoft Corporation) Task: {917E3B44-7C3A-4B91-8449-E4771259837A} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-08-05] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log Task: {9449D998-1D16-4FEF-9271-73FD0E55F82E} - System32\Tasks\Overwolf Updater Task => D:\Arquivos e Downloads\Overwolf\OverwolfUpdater.exe [2484056 2021-11-23] (Overwolf Ltd -> Overwolf LTD) Task: {9939C5A9-B9F5-4F4B-B6AD-6334E4A9C59E} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [275136 2021-08-09] (Bluestack Systems, Inc -> BlueStack Systems, Inc.) Task: {B239B399-4CAA-4AD0-A535-2C3C14B93771} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8386448 2021-12-09] (Microsoft Corporation -> Microsoft Corporation) Task: {B5E12875-810D-464C-94ED-5E8AC8A34918} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1790184 2021-06-21] (Avast Software s.r.o. -> Avast Software) Task: {B5F6EB02-2A27-483D-899B-E64999709DCB} - System32\Tasks\iTopVPN_Update_User => D:\Arquivos e Downloads\iTop VPN\atud.exe [2951168 2021-06-28] (ORANGE VIEW LIMITED -> iTop Inc.) Task: {B8C7B10D-7567-4B5E-8A2C-CEFBCB22791F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {BD2FDA67-7168-4C7C-B468-D8BDA0D0A833} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4969240 2021-12-09] (Avast Software s.r.o. -> AVAST Software) Task: {D6E6A53C-0FC1-47F7-BD91-F68E261CC285} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {DA3DA688-6C12-46FB-9623-1D2EBF4BC460} - System32\Tasks\R@1n-KMS\Windows64Professional => wmic path SoftwareLicensingProduct where (ID="2de67392-b7a7-462a-b1ca-108dd189f588") call Activate Task: {DF0B8720-6F2A-4B79-B89F-8F32D33E03C7} - System32\Tasks\Opera scheduled assistant Autoupdate 1631937685 => C:\Users\User\AppData\Local\Programs\Opera\launcher.exe [42724048 2021-09-13] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\User\AppData\Local\Programs\Opera\assistant" $(Arg0) Task: {E1E29B12-851B-4C3D-838C-C0B5DD620336} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8386448 2021-12-09] (Microsoft Corporation -> Microsoft Corporation) Task: {E38B3157-383D-4D7A-9E2A-3831629C70A2} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB" Task: {F22331D3-741A-4D50-96FC-2AF1C759E3F1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation) (Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.) ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Tcpip\Parameters: [DhcpNameServer] 192.168.100.1 Tcpip\..\Interfaces\{997207c4-de78-4880-8279-d2b376720d12}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{997207c4-de78-4880-8279-d2b376720d12}: [DhcpNameServer] 192.168.100.1 Tcpip\..\Interfaces\{a27020b8-2482-4df6-8a63-b62028881eb9}: [DhcpNameServer] 192.168.100.1 Edge: ======= Edge Extension: (Sem Nome) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [não encontrado (a)] Edge Extension: (Sem Nome) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [não encontrado (a)] Edge Extension: (Sem Nome) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [não encontrado (a)] Edge Extension: (Sem Nome) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [não encontrado (a)] Edge DefaultProfile: Default Edge Profile: C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default [2021-11-09] FireFox: ======== FF DefaultProfile: gfzwf60f.default FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\gfzwf60f.default [2021-09-07] FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\x9iqd2y8.default-release [2021-12-10] FF Plugin: @java.com/DTPlugin,version=11.311.2 -> C:\Program Files\Java\jre1.8.0_311\bin\dtplugin\npDeployJava1.dll [2021-10-21] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.311.2 -> C:\Program Files\Java\jre1.8.0_311\bin\plugin2\npjp2.dll [2021-10-21] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-11-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.15 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-11-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-10-05] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2021-12-13] CHR DownloadDir: D:\Arquivos e Downloads CHR HomePage: Default -> hxxps://www.google.com/ CHR StartupUrls: Default -> "hxxps://www.facebook.com/" CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms} CHR DefaultSearchKeyword: Default -> duckduckgo.com CHR DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list CHR Session Restore: Default -> está habilitado. CHR Extension: (Google Tradutor) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2021-08-23] CHR Extension: (Apresentações) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-06-21] CHR Extension: (Documentos) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2021-06-21] CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-06-21] CHR Extension: (DuckDuckGo) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2021-10-01] CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-06-21] CHR Extension: (Augmented Steam) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnhpnfgdlenaccegplpojghhmaamnnfp [2021-12-07] CHR Extension: (AHA Music - Song Finder para Browser) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpacanjfikmhoddligfbehkpomnbgblf [2021-12-01] CHR Extension: (Planilhas) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-06-21] CHR Extension: (Documentos Google off-line) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-11-30] CHR Extension: (AdBlock — o melhor bloqueador de anúncios) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-12-13] CHR Extension: (Picture-in-Picture Extension (by Google)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkgfoiooedgoejojocmhlaklaeopbecg [2021-06-22] CHR Extension: (SteamDB) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdbmhfkmnlmbkgbabkdealhhbfhlmmon [2021-09-13] CHR Extension: (Steam Profile Assistant) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjmabgdoainclinjecbkdancpamdiaih [2021-06-22] CHR Extension: (MetaMask) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn [2021-12-09] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-06-21] CHR Extension: (Corretor gramatical e ortográfico — LanguageTool) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\oldceeleldhonbafppcapldpdifcinji [2021-12-07] CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-06-21] CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Guest Profile [2021-09-26] CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1 [2021-12-11] CHR Extension: (Apresentações) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-09-07] CHR Extension: (Safe Torrent Scanner) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2021-11-17] CHR Extension: (Documentos) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2021-09-07] CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-09-07] CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-09-07] CHR Extension: (Planilhas) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-09-07] CHR Extension: (Documentos Google off-line) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-11-17] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-09-07] CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-09-07] CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\System Profile [2021-09-26] CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb] Opera: ======= StartMenuInternet: (HKU\S-1-5-21-3341833902-1897029191-1718594085-1001) Opera GXStable - "C:\Users\User\AppData\Local\Programs\Opera GX\Launcher.exe" ==================== Serviços (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.) R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [8480848 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [452888 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [1720088 2021-12-11] (Avast Software s.r.o. -> AVAST Software) R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [452888 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2021-06-21] (Avast Software s.r.o. -> AVAST Software) S4 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8914856 2021-08-10] (BattlEye Innovations e.K. -> ) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12129160 2021-12-02] (Microsoft Corporation -> Microsoft Corporation) S4 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4816272 2021-08-21] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [812520 2021-12-13] (EasyAntiCheat Oy -> Epic Games, Inc) S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [595944 2021-12-09] (EasyAntiCheat Oy -> Epic Games, Inc.) S4 EQU8_19; C:\ProgramData\EQU8\Totally Accurate Battlegrounds\bin\anticheat.x64.equ8.exe [5810832 2021-07-14] (Int3 Software AB -> Int3 Software AB) S4 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.) S4 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [158992 2021-07-19] (IObit Information Technology -> IObit) S4 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.) S4 Origin Client Service; D:\Jogos origin\Origin\OriginClientService.exe [2557656 2021-11-02] (Electronic Arts, Inc. -> Electronic Arts) S4 Origin Web Helper Service; D:\Jogos origin\Origin\OriginWebHelperService.exe [3476184 2021-11-02] (Electronic Arts, Inc. -> Electronic Arts) S4 OverwolfUpdater; D:\Arquivos e Downloads\Overwolf\OverwolfUpdater.exe [2484056 2021-11-23] (Overwolf Ltd -> Overwolf LTD) S4 Parsec; C:\Program Files\Parsec\pservice.exe [396488 2021-08-23] (Parsec Cloud, Inc. -> Parsec) S3 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2021-06-25] (Even Balance, Inc. -> ) S4 reWASDService; D:\Arquivos e Downloads\reWASD\reWASDService.exe [2676472 2021-11-10] (SIA AVB Disc Soft -> Disc Soft Ltd) R2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [14204760 2021-11-18] (ADLICE (ASCOET JULIEN) -> ) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6103464 2021-11-11] (Microsoft Windows Publisher -> Microsoft Corporation) R2 TunnelBearMaintenance; D:\Arquivos e Downloads\TunnelBear\TunnelBear.Maintenance.exe [135752 2021-12-06] (TunnelBear (McAfee Canada ULC) -> TunnelBear) S4 ucldr_battlegrounds_gl; C:\Program Files\Common Files\UNCHEATER\ucldr_battlegrounds_gl.exe [7374576 2021-08-14] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) S3 ucldr_MirTrilogy4_GL; C:\Program Files\Common Files\UNCHEATER\ucldr_MirTrilogy4_GL.exe [6705392 2021-12-07] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe [2872024 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe [128376 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation) S4 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [7550152 2021-08-14] (PUBG CORPORATION -> PUBG Corporation) S2 AdvancedSystemCareService14; "C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe" [X] S4 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_19c79fb6254e3b11\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_19c79fb6254e3b11\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Drivers (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [35720 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [222128 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [368152 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [251928 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [99352 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [21936 2021-10-04] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software) R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [41352 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [185216 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [538992 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [107848 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [82912 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [852752 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [544096 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [214352 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [317680 2021-12-09] (Avast Software s.r.o. -> AVAST Software) R2 BlueStacksDrv_nxt; C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [320728 2021-07-27] (Bluestack Systems, Inc -> Bluestack System Inc.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Arquivo não assinado] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Arquivo não assinado] S3 cpuz145; C:\WINDOWS\temp\cpuz145\cpuz145_x64.sys [49968 2021-09-07] (CPUID -> CPUID) R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2021-08-21] (AVB Disc Soft, SIA -> Disc Soft Ltd) R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2021-08-21] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 EQU8_HELPER_19; C:\WINDOWS\system32\DRIVERS\EQU8_HELPER_19.sys [38032 2021-07-31] (Int3 Software AB -> ) R3 fsfreedomewintun; C:\WINDOWS\System32\drivers\fsfreedomewintun.sys [32272 2021-07-31] (Microsoft Windows Hardware Compatibility Publisher -> F-Secure Corporation) R2 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [176112 2021-05-08] (Bitdefender SRL -> BitDefender LLC) S3 h647906; C:\WINDOWS\System32\drivers\h647906.sys [62576 2008-12-01] (Shen Zhen Dragon Rise Macro Technology Limited Company -> Your Corporation) R3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2019-04-02] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.) S3 hid7906; C:\Windows\SysWOW64\drivers\hid7906.sys [41096 2008-12-01] (Shen Zhen Dragon Rise Macro Technology Limited Company -> Your Corporation) R0 hidgamemap; C:\WINDOWS\System32\drivers\hidgamemap.sys [344784 2021-11-10] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 Imf8HpRegFilter; D:\Arquivos e Downloads\IObit Malware Fighter\drivers\win10_amd64\ImfHpRegFilter.sys [41848 2019-12-17] (IObit Information Technology -> IObit) S3 IMFDownProtect; D:\Arquivos e Downloads\IObit Malware Fighter\drivers\win10_amd64\IMFDownProtect.sys [40328 2020-10-29] (IObit Information Technology -> IObit) S3 IMFForceDelete; D:\Arquivos e Downloads\IObit Malware Fighter\drivers\win10_amd64\IMFForceDelete.sys [34192 2019-06-11] (IObit Information Technology -> IObit) S3 ImfHpFileFilter; D:\Arquivos e Downloads\IObit Malware Fighter\drivers\win10_amd64\ImfHpFileFilter.sys [45432 2019-12-17] (IObit Information Technology -> IObit) S3 ImfObCallback; D:\Arquivos e Downloads\IObit Malware Fighter\drivers\win10_amd64\ImfObCallback.sys [33984 2020-03-12] (IObit Information Technology -> IObit) R2 ImfPfFilter; C:\WINDOWS\system32\drivers\imfpffilter.sys [57840 2020-04-13] (IObit Information Technology -> IObit) R1 steamxbox; C:\WINDOWS\System32\drivers\steamxbox.sys [232792 2021-09-05] (Valve Corp. -> Valve Corporation) R3 tap-tb-0901; C:\WINDOWS\System32\drivers\tap-tb-0901.sys [38656 2021-06-17] (TunnelBear, Inc. -> The OpenVPN Project) U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [38032 2021-12-13] (Adlice -> ) S3 Trufos; C:\WINDOWS\System32\DRIVERS\TRUFOS.sys [439928 2021-05-08] (Bitdefender SRL -> BitDefender S.R.L.) R3 ViGEmBus; C:\WINDOWS\System32\drivers\ViGEmBus.sys [69168 2020-01-10] (Microsoft Windows Hardware Compatibility Publisher -> Benjamin Höglinger-Stelzer) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48520 2021-11-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [435424 2021-11-02] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-11-02] (Microsoft Windows -> Microsoft Corporation) S3 xhunter1; C:\WINDOWS\xhunter1.sys [2522256 2021-12-13] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) S3 AscFileControl; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscFileControl.sys [X] S3 AscFileFilter; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscFileFilter.sys [X] S3 AscRegistryFilter; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscRegistryFilter.sys [X] ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um mês (criados) (Whitelisted) ========= (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2021-12-13 21:32 - 2021-12-13 21:40 - 000062992 _____ C:\Users\User\Desktop\Addition.txt 2021-12-13 21:31 - 2021-12-13 21:41 - 000034917 _____ C:\Users\User\Desktop\FRST.txt 2021-12-13 21:30 - 2021-12-13 21:41 - 000000000 ____D C:\FRST 2021-12-13 21:30 - 2021-12-13 21:30 - 002311168 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe 2021-12-13 18:05 - 2021-12-13 18:05 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2021-12-13 12:23 - 2021-12-13 12:23 - 000038032 _____ C:\WINDOWS\system32\Drivers\truesight.sys 2021-12-12 17:34 - 2021-12-13 21:28 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3341833902-1897029191-1718594085-1001 2021-12-12 17:34 - 2021-12-13 21:28 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3341833902-1897029191-1718594085-1001 2021-12-12 17:33 - 2021-12-12 17:34 - 000002386 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-12-11 19:47 - 2021-12-11 19:47 - 000000000 ____D C:\Users\User\AppData\Local\INetHistory 2021-12-11 18:13 - 2021-12-11 18:13 - 001128650 ____N C:\WINDOWS\Minidump\121121-33343-01.dmp 2021-12-11 02:18 - 2021-12-11 02:18 - 000000905 _____ C:\Users\Public\Desktop\RogueKiller.lnk 2021-12-11 01:51 - 2021-12-11 01:51 - 000008127 _____ C:\Users\User\Desktop\ZHPCleaner (S).html 2021-12-11 01:51 - 2021-12-11 01:51 - 000002010 _____ C:\Users\User\Desktop\ZHPCleaner (S).txt 2021-12-11 01:40 - 2021-12-11 01:40 - 000014360 _____ C:\Users\User\Desktop\ZHPCleaner (R).html 2021-12-11 01:40 - 2021-12-11 01:40 - 000006667 _____ C:\Users\User\Desktop\ZHPCleaner (R).txt 2021-12-10 13:09 - 2021-12-10 13:09 - 000000000 ____D C:\Users\User\AppData\Local\Century 2021-12-10 09:01 - 2021-12-10 09:01 - 000000000 ____D C:\Users\User\AppData\Local\ElevatedDiagnostics 2021-12-09 17:11 - 2021-12-09 17:11 - 000852752 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000544096 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000538992 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetHub.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000368152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000340248 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2021-12-09 17:11 - 2021-12-09 17:11 - 000317680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000251928 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000222128 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000214352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000185216 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000107848 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000099352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000082912 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000041352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000035720 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys 2021-12-09 17:11 - 2021-12-09 17:11 - 000003990 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update 2021-12-07 19:12 - 2021-12-07 19:12 - 000000000 ____D C:\Users\User\AppData\Roaming\Streamlabs Desktop 2021-12-07 14:44 - 2021-12-07 14:44 - 000001187 _____ C:\Users\User\Desktop\MogNetwork - BlueStacks 1.lnk 2021-12-07 12:37 - 2021-12-07 12:37 - 000001742 _____ C:\Users\Public\Desktop\TunnelBear.lnk 2021-12-07 12:37 - 2021-12-07 12:37 - 000000000 ____D C:\Users\User\AppData\Roaming\TunnelBear 2021-12-07 12:37 - 2021-12-07 12:37 - 000000000 ____D C:\Users\User\AppData\Local\TunnelBear 2021-12-07 12:37 - 2021-12-07 12:37 - 000000000 ____D C:\Users\User\AppData\Local\IsolatedStorage 2021-12-07 12:37 - 2021-12-07 12:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TunnelBear 2021-12-07 11:30 - 2021-12-07 11:30 - 000000000 ____D C:\Users\User\OpenVPN 2021-12-07 01:12 - 2021-12-07 01:12 - 000008192 ___SH C:\DumpStack.log.tmp 2021-12-06 22:19 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\Google Keep.lnk 2021-12-06 22:17 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\TF2CraftingAdvisor.lnk 2021-12-06 21:33 - 2021-12-06 21:38 - 000000135 _____ C:\Users\User\Documents\windows 10 ativação.txt 2021-12-06 17:32 - 2021-12-06 17:32 - 000000000 ____D C:\Users\User\AppData\Roaming\.mono 2021-12-06 17:09 - 2021-12-10 20:09 - 000000000 ____D C:\Users\User\AppData\Local\CrashDumps 2021-12-06 03:43 - 2021-12-07 01:12 - 000717970 ____N C:\WINDOWS\Minidump\120721-33625-01.dmp 2021-12-05 00:11 - 2021-12-05 00:11 - 000000000 ____D C:\Users\User\AppData\Local\HodlGod 2021-12-04 19:35 - 2021-12-04 19:35 - 000000000 ____D C:\Users\User\AppData\LocalLow\UpSoft 2021-12-04 19:35 - 2021-12-04 19:35 - 000000000 ____D C:\Users\User\AppData\Local\PatchKit 2021-12-04 19:34 - 2021-12-04 19:34 - 000000775 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HodlGod.lnk 2021-12-04 19:01 - 2021-12-04 19:01 - 000000822 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thetan Arena.lnk 2021-12-04 18:54 - 2021-12-04 18:55 - 000000000 ____D C:\Users\User\AppData\Roaming\immutable-launcher 2021-12-04 18:54 - 2021-12-04 18:54 - 000000000 ____D C:\Users\User\AppData\Local\immutable-launcher-updater 2021-12-04 17:31 - 2021-12-04 17:31 - 000000000 ____D C:\Users\User\AppData\LocalLow\Wolffun 2021-12-01 22:48 - 2021-12-01 22:48 - 000000541 _____ C:\Users\User\Desktop\Music Keeper.lnk 2021-12-01 22:48 - 2021-12-01 22:48 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music Keeper 2021-12-01 22:48 - 2021-12-01 22:48 - 000000000 ____D C:\Users\User\AppData\Local\musickeeper 2021-11-30 23:27 - 2021-11-30 23:34 - 000000000 ____D C:\Users\User\AppData\Roaming\InfinityWallet 2021-11-30 23:26 - 2021-11-30 23:26 - 000002438 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InfinityWallet.lnk 2021-11-30 23:26 - 2021-11-30 23:26 - 000002430 _____ C:\Users\User\Desktop\InfinityWallet.lnk 2021-11-30 23:26 - 2021-11-30 23:26 - 000000000 ____D C:\Users\User\AppData\Local\infinitywallet-updater 2021-11-30 22:34 - 2021-11-30 22:34 - 000001223 _____ C:\Users\User\Desktop\WEMIXWallet - BlueStacks 1.lnk 2021-11-30 22:30 - 2021-11-30 22:30 - 000001223 _____ C:\Users\User\Desktop\WEMIXWallet.lnk 2021-11-30 11:28 - 2021-12-13 21:28 - 000003502 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1624670633 2021-11-30 11:28 - 2021-11-30 11:28 - 000001435 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navegador Opera GX.lnk 2021-11-29 13:55 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\G-Loot.lnk 2021-11-29 12:04 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\Outplayed.lnk 2021-11-29 12:04 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\Apex Legends Tracker.lnk 2021-11-29 12:02 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\GamersXP.lnk 2021-11-29 12:00 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\LoLTheory.lnk 2021-11-29 12:00 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\LoLCooldown.lnk 2021-11-29 12:00 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\LoLalytics Builds.lnk 2021-11-29 11:59 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\Facecheck.lnk 2021-11-29 11:58 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\LoLwiz.lnk 2021-11-29 11:58 - 2021-11-29 12:04 - 000000000 ____D C:\Users\User\AppData\Roaming\Overwolf 2021-11-29 08:55 - 2021-11-29 08:55 - 000000223 _____ C:\Users\User\Desktop\Tetris® Effect Connected.url 2021-11-28 14:10 - 2021-11-25 14:28 - 000205707 _____ C:\Users\User\Desktop\PSICOLOGIA SOCIAL - REVISÃO (1).pdf 2021-11-27 16:16 - 2021-12-13 18:07 - 002522256 _____ (Wellbia.com Co., Ltd.) C:\WINDOWS\xhunter1.sys 2021-11-27 13:15 - 2021-11-27 13:15 - 000000000 ____D C:\Users\User\AppData\Local\NBGI 2021-11-26 15:14 - 2021-12-13 21:10 - 000002011 _____ C:\Users\User\Desktop\Porofessor.gg.lnk 2021-11-25 18:29 - 2021-11-25 18:29 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Citra 2021-11-25 13:25 - 2021-11-25 13:25 - 000000000 ____D C:\Users\User\Desktop\package 2021-11-24 23:48 - 2021-11-24 23:50 - 000000000 ____D C:\Users\User\AppData\Local\Mir4Launcher 2021-11-24 23:48 - 2021-11-24 23:48 - 000000824 _____ C:\Users\Public\Desktop\Mir4Global.lnk 2021-11-24 23:48 - 2021-11-24 23:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wemade 2021-11-24 18:37 - 2021-11-24 18:37 - 000000000 ____D C:\Users\User\AppData\Roaming\Klei 2021-11-22 13:10 - 2021-11-22 13:10 - 000025576 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\eac_usermode_25522388249547.dll 2021-11-22 00:12 - 2021-11-22 00:11 - 001111512 ____N C:\WINDOWS\Minidump\112221-37484-01.dmp 2021-11-21 12:02 - 2021-12-13 21:28 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2021-11-21 12:02 - 2021-11-21 12:02 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2021-11-19 18:35 - 2021-12-13 21:28 - 000002330 _____ C:\WINDOWS\system32\Tasks\iTopVPN_SkipUAC_User 2021-11-19 18:34 - 2021-12-13 21:28 - 000002340 _____ C:\WINDOWS\system32\Tasks\IMF_SkipUAC_User 2021-11-17 21:26 - 2021-11-17 21:26 - 000000000 ____D C:\Users\User\AppData\Local\HaloInfinite 2021-11-17 20:20 - 2021-11-17 20:20 - 000428492 _____ C:\Users\User\Desktop\AEP Depressão e a Paternidade-completo.pdf 2021-11-16 15:31 - 2021-11-16 15:31 - 000000000 ____D C:\Users\User\Desktop\ptde 2021-11-16 15:31 - 2021-11-16 15:31 - 000000000 ____D C:\Users\User\Desktop\dsr 2021-11-15 16:25 - 2021-11-15 16:25 - 000000000 ____D C:\Users\User\Documents\FromSoftware 2021-11-15 16:25 - 2021-11-15 16:25 - 000000000 ____D C:\Users\User\AppData\Local\FromSoftware 2021-11-15 15:25 - 2021-11-27 16:24 - 000000000 ____D C:\Users\User\Documents\NBGI ==================== Um mês (modificados) ================== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2021-12-13 21:41 - 2021-06-21 10:11 - 000000000 ____D C:\Program Files (x86)\Google 2021-12-13 21:29 - 2021-07-31 15:47 - 000000000 ____D C:\Users\User\AppData\Roaming\IObit 2021-12-13 21:29 - 2021-06-22 14:57 - 000000000 ____D C:\Users\User\AppData\Roaming\discord 2021-12-13 21:28 - 2021-10-06 17:03 - 000003248 _____ C:\WINDOWS\system32\Tasks\Overwolf Updater Task 2021-12-13 21:28 - 2021-09-18 01:01 - 000003826 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1631937685 2021-12-13 21:28 - 2021-09-18 01:01 - 000003580 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1631937680 2021-12-13 21:28 - 2021-09-17 10:56 - 000003546 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-12-13 21:28 - 2021-09-17 10:56 - 000003322 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2021-12-13 21:28 - 2021-09-14 21:47 - 000003398 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2021-12-13 21:28 - 2021-09-14 21:47 - 000003196 _____ C:\WINDOWS\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2021-12-13 21:28 - 2021-09-14 21:47 - 000003152 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2021-12-13 21:28 - 2021-09-14 21:47 - 000002984 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2021-12-13 21:28 - 2021-09-14 21:47 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2021-12-13 21:28 - 2021-09-14 21:47 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2021-12-13 21:28 - 2021-09-14 21:47 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2021-12-13 21:28 - 2021-09-14 21:47 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2021-12-13 21:28 - 2021-09-14 21:47 - 000002914 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2021-12-13 21:28 - 2021-09-14 21:47 - 000002744 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2021-12-13 21:28 - 2021-08-16 00:07 - 000002958 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper_nxt 2021-12-13 21:28 - 2021-08-14 14:24 - 000002398 _____ C:\WINDOWS\system32\Tasks\Uninstaller_SkipUac_User 2021-12-13 21:28 - 2021-07-31 17:53 - 000002506 _____ C:\WINDOWS\system32\Tasks\iTopVPN_Update_User 2021-12-13 21:28 - 2021-07-31 17:53 - 000002436 _____ C:\WINDOWS\system32\Tasks\iTopVPN_Scheduler_User 2021-12-13 21:28 - 2021-07-31 16:16 - 000002646 _____ C:\WINDOWS\system32\Tasks\ASC_PerformanceMonitor 2021-12-13 21:28 - 2021-07-31 16:16 - 000002534 _____ C:\WINDOWS\system32\Tasks\ASC_SkipUac_User 2021-12-13 21:28 - 2021-07-31 16:10 - 000002590 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask 2021-12-13 21:28 - 2021-07-03 23:24 - 000003324 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{81967E02-468F-4D52-B491-248E27A196F3} 2021-12-13 21:28 - 2021-06-21 12:31 - 000000000 ____D C:\Program Files (x86)\Steam 2021-12-13 21:28 - 2021-06-21 11:50 - 000003518 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2021-12-13 21:28 - 2021-06-21 11:50 - 000003294 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2021-12-13 21:28 - 2021-06-21 11:50 - 000003080 _____ C:\WINDOWS\system32\Tasks\klcp_update 2021-12-13 21:26 - 2021-06-22 14:57 - 000000000 ____D C:\Users\User\AppData\Local\Discord 2021-12-13 21:10 - 2021-10-06 17:02 - 000000000 ____D C:\Users\User\AppData\Local\Overwolf 2021-12-13 21:08 - 2020-06-04 13:03 - 000000000 ____D C:\ProgramData\NVIDIA 2021-12-13 18:05 - 2019-12-07 06:13 - 000000000 ____D C:\WINDOWS\INF 2021-12-13 17:49 - 2021-06-22 16:44 - 000000000 ____D C:\Users\User\AppData\Local\D3DSCache 2021-12-13 17:49 - 2019-12-07 06:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-12-13 17:42 - 2021-06-21 10:12 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2021-12-13 17:42 - 2021-06-21 10:12 - 000002204 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2021-12-13 16:27 - 2021-06-21 11:55 - 001769482 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-12-13 16:27 - 2019-12-07 11:53 - 000761750 _____ C:\WINDOWS\system32\prfh0416.dat 2021-12-13 16:27 - 2019-12-07 11:53 - 000153514 _____ C:\WINDOWS\system32\prfc0416.dat 2021-12-13 12:27 - 2021-09-18 16:24 - 000000000 ___HD C:\Users\User\Downloads\.opera 2021-12-13 12:27 - 2021-09-18 16:24 - 000000000 ___HD C:\Users\User\.opera 2021-12-13 12:26 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-12-13 12:22 - 2021-06-21 11:50 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-12-13 12:22 - 2021-06-21 10:52 - 000000000 ____D C:\ProgramData\Avast Software 2021-12-13 04:38 - 2019-12-07 06:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2021-12-13 03:29 - 2019-12-07 06:14 - 000000000 ___HD C:\Program Files\WindowsApps 2021-12-12 14:54 - 2021-06-23 09:30 - 000000000 ____D C:\Users\User\AppData\Roaming\slobs-client 2021-12-12 13:30 - 2021-06-21 11:46 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-12-12 13:30 - 2020-06-04 11:20 - 000000000 ____D C:\Users\User\AppData\Local\ConnectedDevicesPlatform 2021-12-11 21:12 - 2021-06-21 11:50 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software 2021-12-11 19:44 - 2020-06-04 11:20 - 000000000 __RHD C:\Users\Public\AccountPictures 2021-12-11 18:13 - 2021-06-25 13:45 - 000000000 ____D C:\WINDOWS\Minidump 2021-12-11 15:30 - 2021-06-21 12:33 - 000000000 ____D C:\Users\User\AppData\Local\Avast Software 2021-12-11 14:51 - 2021-06-23 13:35 - 000000000 ____D C:\Users\User\AppData\Roaming\Origin 2021-12-11 14:40 - 2021-06-23 13:35 - 000000000 ____D C:\ProgramData\Origin 2021-12-11 14:39 - 2021-06-23 13:35 - 000000000 ____D C:\Users\User\AppData\Local\Origin 2021-12-11 02:18 - 2021-09-07 17:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller 2021-12-11 02:18 - 2021-09-07 17:34 - 000000000 ____D C:\Program Files\RogueKiller 2021-12-11 01:53 - 2021-07-31 15:48 - 000000000 ____D C:\ProgramData\ProductData 2021-12-11 01:52 - 2021-09-07 17:06 - 000000000 ____D C:\Users\User\AppData\Roaming\ZHP 2021-12-11 01:52 - 2021-07-31 15:47 - 000000000 ____D C:\ProgramData\IObit 2021-12-11 01:26 - 2021-09-07 17:06 - 000000876 _____ C:\Users\User\Desktop\ZHPCleaner.lnk 2021-12-11 01:23 - 2021-07-31 15:57 - 000000000 ____D C:\WINDOWS\system32\appmgmt 2021-12-11 01:18 - 2021-10-06 17:03 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2021-12-10 13:09 - 2021-06-24 22:45 - 000000000 ____D C:\Users\User\AppData\Local\UnrealEngine 2021-12-10 13:09 - 2021-06-22 19:55 - 000000000 ____D C:\Users\User\AppData\Roaming\EasyAntiCheat 2021-12-10 09:15 - 2021-07-31 17:53 - 000000000 ____D C:\ProgramData\iTop VPN 2021-12-10 01:18 - 2019-12-07 06:03 - 000000000 ____D C:\WINDOWS\servicing 2021-12-10 01:18 - 2019-12-07 06:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-12-09 18:47 - 2021-06-22 22:12 - 000000000 ____D C:\Program Files\Microsoft Office 2021-12-09 17:11 - 2019-12-07 06:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2021-12-07 19:12 - 2021-07-06 18:31 - 000000000 ____D C:\Program Files\Streamlabs OBS 2021-12-07 12:37 - 2020-06-04 13:03 - 000000000 ____D C:\ProgramData\Package Cache 2021-12-06 12:30 - 2020-06-04 11:20 - 000000000 ____D C:\Users\User\AppData\Local\Packages 2021-12-04 17:22 - 2021-06-25 00:48 - 000000000 ____D C:\ProgramData\Epic 2021-11-28 13:58 - 2020-06-04 13:06 - 000000000 ____D C:\Users\User\AppData\Local\NVIDIA Corporation 2021-11-28 00:31 - 2021-07-03 23:23 - 000000000 ____D C:\Users\User\AppData\Local\LogMeIn Hamachi 2021-11-26 14:26 - 2021-10-29 21:12 - 000000000 ____D C:\ProgramData\Riot Games 2021-11-24 23:53 - 2021-08-14 23:30 - 000000000 ____D C:\Users\User\AppData\Local\WELLBIA 2021-11-24 23:53 - 2021-08-14 23:30 - 000000000 ____D C:\Program Files\Common Files\UNCHEATER 2021-11-24 00:32 - 2021-10-04 23:45 - 000000000 ____D C:\Users\User\AppData\Roaming\.minecraft 2021-11-23 20:29 - 2021-06-22 21:16 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox 2021-11-22 18:09 - 2020-06-04 11:16 - 000000000 ____D C:\ProgramData\Packages 2021-11-17 20:41 - 2021-11-09 18:31 - 002224592 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll 2021-11-17 20:41 - 2021-11-09 18:31 - 000332224 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll 2021-11-17 20:41 - 2021-11-09 18:31 - 000217536 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll 2021-11-17 20:41 - 2021-11-09 18:31 - 000197048 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll 2021-11-17 20:41 - 2021-11-09 18:31 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll 2021-11-17 20:41 - 2021-11-09 18:31 - 000061904 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamemodcontrol.exe 2021-11-16 18:27 - 2021-06-21 10:54 - 000002088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk 2021-11-16 18:27 - 2021-06-21 10:54 - 000002076 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2021-11-15 23:10 - 2021-06-25 21:57 - 000000000 ____D C:\Users\User\Documents\My Games 2021-11-14 16:58 - 2021-08-28 14:06 - 000000000 ____D C:\Users\User\AppData\Roaming\vlc ==================== Arquivos na raiz de alguns diretórios ======== 2021-11-09 21:28 - 2021-11-09 21:28 - 003290776 _____ (Nicolas Coolman) C:\Users\User\ZHPCleaner.exe 2021-06-25 21:56 - 2021-06-25 21:56 - 000000092 _____ () C:\Users\User\AppData\Local\fusioncache.dat 2021-08-31 15:59 - 2021-08-31 15:59 - 000002258 _____ () C:\Users\User\AppData\Local\recently-used.xbel ==================== SigCheck ============================ (Não há correção automática para arquivos que não passaram na verificação.) ==================== Fim de FRST.txt ========================