Resultado do análise da Farbar Recovery Scan Tool (FRST) (x64) Versão: 22-01-2022 Executado por del_bone (administrador) em DEL_BONE (23-01-2022 06:36:48) Executando a partir de C:\Users\rabar\Desktop Perfis Carregados: del_bone Plataforma: Microsoft Windows 10 Pro Versão 21H1 19043.1466 (X64) Idioma: Português (Brasil) Navegador padrão: FF Modo da Inicialização: Normal ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\protectedservice.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Maintenance.exe (Malwarebytes Inc -> Malwarebytes) C:\Users\rabar\Desktop\adwcleaner_8.3.1.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_3.60.12001.0_x64__8wekyb3d8bbwe\gamingservices.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_3.60.12001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MsMpEng.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) C:\Program Files\Topaz OFD\Warsaw\core.exe <2> ==================== Registro (Whitelisted) =================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [881440 2019-06-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [SACMonitor] => C:\Program Files\SafeNet\Authentication\SAC\x64\SACMonitor.exe [655392 2018-03-26] (gemalto -> Gemalto) HKLM-x32\...\Run: [Avira System Speedup User Starter] => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [334984 2021-11-29] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [486464 2020-10-01] (geek software GmbH -> geek software GmbH) HKU\S-1-5-21-652207974-1608278505-3514412468-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [33770112 2021-05-20] (Piriform Software Ltd -> Piriform Software Ltd) HKU\S-1-5-21-652207974-1608278505-3514412468-1002\...\Run: [Lync] => C:\Program Files\Microsoft Office\root\Office16\lync.exe [26599728 2022-01-14] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-652207974-1608278505-3514412468-1006\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [669112 2019-10-31] (OpenVPN Inc. -> ) HKU\S-1-5-21-652207974-1608278505-3514412468-1006\...\Run: [MicrosoftEdgeAutoLaunch_8034C7563A62DB6EE0E2548078706C1A] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 HKLM\Software\Microsoft\Active Setup\Installed Components: [OpenVPN_UserSetup] -> reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /t REG_SZ /d "C:\Program Files\OpenVPN\bin\openvpn-gui.exe" /f HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\97.0.4692.71\Installer\chrmstp.exe [2022-01-10] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{73FA19D0-2D75-11D2-995D-00C04F98BBC9}] -> HKLM\SOFTWARE\Policies\Google: Restrição <==== ATENÇÃO ==================== Tarefas Agendadas (Whitelisted) ============ (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) Task: {065EA9C0-24AF-4716-8E04-BB25BCDEB171} - \Rerun Warsaw's CoreFixer -> Nenhum Arquivo <==== ATENÇÃO Task: {0D7F2372-2AE8-4872-95B6-D58F5C25D761} - System32\Tasks\PostponeDeviceSetupToast_S-1-5-21-652207974-1608278505-3514412468-1002_1 => {5ded83ef-1e99-48cf-bf83-676d2a6db408} C:\Windows\System32\oobe\UserOOBE.dll [420864 2021-12-17] (Microsoft Windows -> Microsoft Corporation) Task: {187823DF-5EE7-452F-9E84-547AFCCE1DAF} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22844272 2022-01-10] (Microsoft Corporation -> Microsoft Corporation) Task: {1A4A5E25-4796-4477-B30A-5748D97D52D0} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-05-20] (Piriform Software Ltd -> Piriform) Task: {1DC62895-EDD4-4E99-8A79-E4595591A0DE} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-652207974-1608278505-3514412468-1002 => C:\Users\rabar\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (Nenhum Arquivo) Task: {2CB76234-66C8-491C-AE15-BBB4D2C91815} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1724928 2020-02-26] () [Arquivo não assinado] Task: {416A7DB4-B7B5-43FE-BB4F-A54B15D46D68} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\MpCmdRun.exe [901048 2022-01-22] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {46842264-32BC-41EB-A1AA-EDAA5D62982F} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138592 2022-01-14] (Microsoft Corporation -> Microsoft Corporation) Task: {5E17A9A1-EA0B-4B20-8865-6B3724647AC8} - System32\Tasks\Online_KMS_Activation_Script-Renewal => %windir%\Online_KMS_Activation_Script\Online_KMS_Activation_Script-Renewal.cmd (Nenhum Arquivo) Task: {600CF363-27B3-4B4E-820E-1D94C7B80E57} - System32\Tasks\Avira_Security_Update => C:\WINDOWS\system32\net.exe [59904 2019-12-07] (Microsoft Windows -> Microsoft Corporation) Task: {6984C13E-B13E-4D26-89F1-EB0C2A7950D7} - System32\Tasks\Avira_Security_Service_SCM_Watchdog => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe [254640 2021-12-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) Task: {868E6DCA-69BC-437A-B022-9824257741A6} - System32\Tasks\Avira_Security_Maintenance => Command(1): C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe -> FallbackTelemetry Task: {868E6DCA-69BC-437A-B022-9824257741A6} - System32\Tasks\Avira_Security_Maintenance => Command(2): C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe -> ServiceWatchdog Task: {868E6DCA-69BC-437A-B022-9824257741A6} - System32\Tasks\Avira_Security_Maintenance => Command(3): C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe -> CrashCollector Task: {89F7CF48-4B84-4FAA-9FCB-A94449ABFFFB} - System32\Tasks\Avira_Security_Systray => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Systray.Application.exe [1657440 2021-12-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) Task: {902FFB0A-1B0C-4740-BF00-38E1F845A407} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138592 2022-01-14] (Microsoft Corporation -> Microsoft Corporation) Task: {9711B567-27BC-4DA5-93B3-023162561194} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXvGPUDisableTask => C:\WINDOWS\System32\RemoteFXvGPUDisablement.exe Disable (Nenhum Arquivo) Task: {A3A82A0F-9287-48AC-BBAE-E35DE6489376} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\MpCmdRun.exe [901048 2022-01-22] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {A4FFF011-7C0B-4E59-87DA-5902CF2AD6D3} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-652207974-1608278505-3514412468-500 => C:\Users\rabar\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (Nenhum Arquivo) Task: {ADFBEA6F-A682-4F08-A408-8BB4D9F05AA3} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-652207974-1608278505-3514412468-1006 => C:\Users\rabar\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (Nenhum Arquivo) Task: {B4DBBCDB-8BC0-4F3D-9FF4-7055132C4F49} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-11] (Google LLC -> Google LLC) Task: {BB3A8A75-D120-4A2A-A87F-1B62333F5ADE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [28158080 2021-05-20] (Piriform Software Ltd -> Piriform Software Ltd) Task: {BC679E1C-7824-4B9F-93EC-224B38AABD3E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-11] (Google LLC -> Google LLC) Task: {BD8A6CFC-DA4C-4724-A3E5-8FE7A48EDFF0} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-652207974-1608278505-3514412468-1006 => C:\Users\rabar\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (Nenhum Arquivo) Task: {C53C2ABA-8CBA-4832-845B-718F02279A45} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB" Task: {C7587666-E453-48B9-9CDF-47881A8FCC07} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXWarningTask => C:\WINDOWS\System32\RemoteFXvGPUDisablement.exe Warning (Nenhum Arquivo) Task: {D0BEEF50-8EDC-402C-8A61-E0296E70BD14} - System32\Tasks\AviraSystemSpeedupUpdate => C:\ProgramData\Avira\SystemSpeedup\Update\avira_speedup_setup_update.exe [30215736 2022-01-13] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) Task: {D1844AAC-6EE2-4EEF-BD68-FE60E7FFB46B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8413176 2022-01-14] (Microsoft Corporation -> Microsoft Corporation) Task: {D7267300-54E8-4FB2-9104-7233E99DBE72} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\MpCmdRun.exe [901048 2022-01-22] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {E11650FF-B647-460B-878F-31E08B1374CB} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22844272 2022-01-10] (Microsoft Corporation -> Microsoft Corporation) Task: {E2853646-0BFE-4641-A642-A3149667075C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\MpCmdRun.exe [901048 2022-01-22] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {E6A90C21-7D60-42E8-90FE-695DE877FAC4} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2648424 2021-10-27] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) Task: {E9066E3C-FDF1-417D-BCB6-8C9A00FB122D} - System32\Tasks\Avira\System Speedup\TestScheduler => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [334984 2021-11-29] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) Task: {EEC67C71-AF2B-4D9B-85F6-7F373EE9D231} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8413176 2022-01-14] (Microsoft Corporation -> Microsoft Corporation) (Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.) ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3: <==== ATENÇÃO (Restrição - Zones) Tcpip\Parameters: [DhcpNameServer] 181.213.132.2 181.213.132.3 Tcpip\..\Interfaces\{ba074d06-f2d2-4788-b6ae-2ff961e2f004}: [DhcpNameServer] 181.213.132.2 181.213.132.3 Edge: ======= DownloadDir: C:\Users\rabar\Downloads Edge Extension: (Sem Nome) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [não encontrado (a)] Edge Extension: (Sem Nome) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [não encontrado (a)] Edge Extension: (Sem Nome) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [não encontrado (a)] Edge Extension: (Sem Nome) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [não encontrado (a)] Edge Profile: C:\Users\rabar\AppData\Local\Microsoft\Edge\User Data\Default [2022-01-22] Edge DownloadDir: Default -> C:\Users\rabar\Downloads FireFox: ======== FF DefaultProfile: pv583qgr.default FF ProfilePath: C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\pv583qgr.default [2020-01-18] FF Extension: (Avira Password Manager) - C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\pv583qgr.default\Extensions\passwordmanager@avira.com [2022-01-20] FF ProfilePath: C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\gbzqbqas.default-release [2022-01-23] FF Session Restore: Mozilla\Firefox\Profiles\gbzqbqas.default-release -> está habilitado. FF Extension: (Dark Reader) - C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\gbzqbqas.default-release\Extensions\addon@darkreader.org.xpi [2021-11-02] FF Extension: (SteamDB) - C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\gbzqbqas.default-release\Extensions\firefox-extension@steamdb.info.xpi [2021-11-02] FF Extension: (To Google Translate) - C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\gbzqbqas.default-release\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2021-06-29] FF Extension: (Flagfox) - C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\gbzqbqas.default-release\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2021-11-02] FF Extension: (Groovy Blue) - C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\gbzqbqas.default-release\Extensions\{6149213c-39c0-4bad-8ffa-f0bff06e96f8}.xpi [2020-01-11] FF Extension: (NoScript) - C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\gbzqbqas.default-release\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2021-08-27] FF Extension: (Adblock Plus - bloqueador de anúncios grátis) - C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\gbzqbqas.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2021-11-02] FF Extension: (Dark Fox) - C:\Users\rabar\AppData\Roaming\Mozilla\Firefox\Profiles\gbzqbqas.default-release\Extensions\{e7fe4ffe-f256-4f85-906d-072fdd698585}.xpi [2020-01-11] FF Plugin: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2020-01-11] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2020-01-11] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1225195.dll [2016-09-20] (Adobe Systems, Inc.) [Arquivo não assinado] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-10-29] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-07-19] (VideoLAN) [Arquivo não assinado] FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\autoconf_warsaw.js [2022-01-21] Chrome: ======= CHR Profile: C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default [2022-01-22] CHR Notifications: Default -> hxxps://br.gearbest.com; hxxps://meet.google.com; hxxps://minhaclaroresidencial.claro.com.br; hxxps://www.facebook.com; hxxps://www.gearbest.com CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxps://www.google.com.br/","hxxp://interno.nutec.com.br/intranet" CHR Extension: (Apresentações) - C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-01-11] CHR Extension: (Documentos) - C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-01-11] CHR Extension: (Google Drive) - C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-26] CHR Extension: (YouTube) - C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-01-11] CHR Extension: (Avira Safe Shopping) - C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2022-01-20] CHR Extension: (Escorrega O Preço) - C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecikoeehpobhkjagenjmldoehmcmeioo [2022-01-20] CHR Extension: (Folhas de cálculo) - C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-01-11] CHR Extension: (Google Docs offline) - C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-01-20] CHR Extension: (Pagamentos via Chrome Web Store) - C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-31] CHR Extension: (Gmail) - C:\Users\rabar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-26] CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] CHR HKLM\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] Opera: ======= OPR Profile: C:\Users\rabar\AppData\Roaming\Opera Software\Opera Stable [2021-05-29] OPR Extension: (Segurança do navegador Avira) - C:\Users\rabar\AppData\Roaming\Opera Software\Opera Stable\Extensions\dalelnnofafalcmkmnhdbigbjjkloabo [2020-01-11] OPR Extension: (Avira Password Manager) - C:\Users\rabar\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngohaaocccbohaffogpbgfpmpgbcgccg [2020-01-11] OPR Extension: (Free Avira Phantom VPN – Unblock Websites) - C:\Users\rabar\AppData\Roaming\Opera Software\Opera Stable\Extensions\pcgkmkjdikhiodinhloioejnpjgmfigd [2020-01-11] ==================== Serviços (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1206648 2021-07-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R2 AntivirProtectedService; C:\Program Files (x86)\Avira\Antivirus\ProtectedService.exe [538000 2021-07-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [485048 2021-07-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [485048 2021-07-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [574832 2022-01-19] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R2 AviraOptimizerHost; C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe [2998096 2021-11-23] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R2 AviraSecurity; C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.exe [263984 2021-12-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) S2 AviraSecurityUpdater; C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Common.Updater.exe [263472 2021-12-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R2 AviraUpdaterService; C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe [159080 2021-04-13] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12119432 2022-01-10] (Microsoft Corporation -> Microsoft Corporation) S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv2.exe [24192 2018-03-06] (OpenVPN Technologies, Inc. -> ) S3 OpenVPNServiceInteractive; C:\Program Files\OpenVPN\bin\openvpnserv.exe [66488 2019-10-31] (OpenVPN Inc. -> The OpenVPN Project) S3 OpenVPNServiceLegacy; C:\Program Files\OpenVPN\bin\openvpnserv.exe [66488 2019-10-31] (OpenVPN Inc. -> The OpenVPN Project) S3 PDF24; C:\Program Files (x86)\PDF24\pdf24.exe [486464 2020-10-01] (geek software GmbH -> geek software GmbH) S2 SACSrv; C:\Program Files\SafeNet\Authentication\SAC\x64\SACSRV.exe [59424 2018-03-26] (gemalto -> Gemalto) S2 scpbradserv; C:\Program Files (x86)\scpbrad\scpbradserv.exe [2269056 2021-02-25] (Banco Bradesco S.A. -> Scopus Soluções em TI Ltda) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6137040 2022-01-14] (Microsoft Windows Publisher -> Microsoft Corporation) R2 Warsaw Technology; C:\Program Files\Topaz OFD\Warsaw\core.exe [975472 2021-02-10] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\NisSrv.exe [2876152 2022-01-22] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\MsMpEng.exe [128360 2022-01-22] (Microsoft Windows Publisher -> Microsoft Corporation) S3 Rockstar Service; "E:\Rafael\Games\Launcher\RockstarService.exe" [X] ===================== Drivers (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R3 AKSIFDH; C:\WINDOWS\System32\drivers\aksifdh.sys [62632 2015-01-23] (Aladdin Knowledge Systems Inc. -> Aladdin Knowledge Systems, Ltd.) S3 AKSUP; C:\WINDOWS\system32\drivers\aksup.sys [44712 2015-01-23] (Aladdin Knowledge Systems Inc. -> Aladdin Knowledge Systems, Ltd.) R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0373652.inf_amd64_97d024528a122d1a\B372726\amdkmdag.sys [80538504 2021-11-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) S3 AsrDrv103; C:\WINDOWS\SysWOW64\Drivers\AsrDrv103.sys [34568 2020-01-11] (ASROCK Incorporation -> ASRock Incorporation) [Arquivo não assinado] R0 avdevprot; C:\WINDOWS\System32\DRIVERS\avdevprot.sys [78936 2019-06-07] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) S0 avelam; C:\WINDOWS\System32\drivers\avelam.sys [22848 2021-07-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Avira Operations GmbH & Co. KG) R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [209088 2021-10-27] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [199312 2021-03-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [46704 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [89736 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R0 avusbflt; C:\WINDOWS\System32\Drivers\avusbflt.sys [45472 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Arquivo não assinado] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Arquivo não assinado] R1 EneTechIo; C:\WINDOWS\system32\drivers\ene.sys [20992 2020-05-12] (Microsoft Windows Hardware Compatibility Publisher -> ) R1 GLCKIO2; C:\WINDOWS\system32\drivers\GLCKIO2.sys [19392 2018-04-23] (ASUSTeK Computer Inc. -> ) S3 MSIO; C:\Program Files (x86)\ASRock Utility\ASRRGBLED\Bin\msio64.sys [25616 2019-10-31] (MICSYS Technology Co., Ltd. -> ) R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39920 2019-10-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48536 2022-01-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [435432 2022-01-22] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86248 2022-01-22] (Microsoft Windows -> Microsoft Corporation) R1 wsddfac; C:\WINDOWS\System32\drivers\wsddfac.sys [47800 2022-01-21] (Gas Informatica Ltda -> GAS Tecnologia) R1 wsddntf; C:\WINDOWS\system32\DRIVERS\wsddntf.sys [51160 2021-02-11] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) R1 wsddpp; C:\WINDOWS\system32\drivers\wsddpp.sys [34768 2021-02-11] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) R3 wsddprm; C:\WINDOWS\system32\drivers\wsddprm.sys [33728 2021-02-10] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um mês (criados) (Whitelisted) ========= (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2022-01-23 06:36 - 2022-01-23 06:37 - 000027846 _____ C:\Users\rabar\Desktop\FRST.txt 2022-01-23 06:36 - 2022-01-23 06:37 - 000000000 ____D C:\FRST 2022-01-23 06:35 - 2022-01-23 06:35 - 000001678 _____ C:\Users\rabar\Desktop\AdwCleaner[C00].txt 2022-01-23 06:33 - 2022-01-23 06:34 - 000000000 ____D C:\AdwCleaner 2022-01-23 05:40 - 2022-01-23 05:40 - 008540344 _____ (Malwarebytes) C:\Users\rabar\Desktop\adwcleaner_8.3.1.exe 2022-01-23 05:40 - 2022-01-23 05:40 - 002311680 _____ (Farbar) C:\Users\rabar\Desktop\FRST64.exe 2022-01-20 17:26 - 2022-01-20 17:26 - 000012565 _____ C:\Users\rabar\Desktop\ZA-Scan.txt 2022-01-20 17:18 - 2022-01-20 17:18 - 000012565 _____ C:\ZA-Scan.txt 2022-01-20 17:10 - 2018-04-18 00:39 - 002038755 _____ C:\Users\rabar\Desktop\ZA-Scan.exe 2022-01-20 17:02 - 2022-01-20 17:02 - 000004036 _____ C:\WINDOWS\system32\Tasks\PostponeDeviceSetupToast_S-1-5-21-652207974-1608278505-3514412468-1002_1 2022-01-20 06:00 - 2022-01-21 17:06 - 101449728 _____ C:\WINDOWS\system32\config\SOFTWARE 2022-01-20 05:53 - 2022-01-20 06:00 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware 2022-01-15 11:04 - 2022-01-15 11:04 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2022-01-14 00:36 - 2022-01-14 00:36 - 000523776 _____ (curl, hxxps://curl.se/) C:\WINDOWS\system32\curl.exe 2022-01-14 00:36 - 2022-01-14 00:36 - 000464384 _____ (curl, hxxps://curl.se/) C:\WINDOWS\SysWOW64\curl.exe 2022-01-14 00:36 - 2022-01-14 00:36 - 000011797 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2022-01-14 00:23 - 2022-01-14 00:25 - 000000000 ___HD C:\$WinREAgent 2021-12-27 12:30 - 2022-01-20 09:47 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-652207974-1608278505-3514412468-1006 2021-12-26 15:43 - 2021-12-26 15:43 - 000058707 _____ C:\Users\rabar\Desktop\NF Centauro.pdf 2021-12-26 15:37 - 2021-12-26 15:37 - 000212544 _____ C:\Users\rabar\Desktop\CV.pdf ==================== Um mês (modificados) ================== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2022-01-23 06:34 - 2019-12-07 06:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2022-01-23 06:33 - 2020-01-11 06:46 - 000000000 ____D C:\Users\rabar\AppData\LocalLow\Mozilla 2022-01-23 05:52 - 2020-01-11 07:14 - 000000000 ____D C:\Program Files (x86)\Google 2022-01-23 05:41 - 2020-01-11 09:39 - 000000000 ____D C:\Users\rabar\AppData\Roaming\vlc 2022-01-23 05:41 - 2020-01-11 08:19 - 000000000 ____D C:\Users\rabar\AppData\Roaming\uTorrent 2022-01-22 21:21 - 2020-01-11 08:03 - 000000000 ____D C:\Program Files\CCleaner 2022-01-22 15:47 - 2020-01-11 08:19 - 000001012 _____ C:\Users\rabar\Downloads\µTorrent.lnk 2022-01-22 14:03 - 2021-06-04 07:55 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2022-01-22 14:03 - 2019-12-07 06:14 - 000000000 ___HD C:\Program Files\WindowsApps 2022-01-22 14:03 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2022-01-22 08:46 - 2019-11-21 04:32 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2022-01-21 17:31 - 2020-03-20 09:50 - 000047800 _____ (GAS Tecnologia) C:\WINDOWS\system32\Drivers\wsddfac.sys 2022-01-21 17:31 - 2020-01-11 06:46 - 000000000 ____D C:\Program Files\Mozilla Firefox 2022-01-21 17:15 - 2020-01-11 08:47 - 000001174 _____ C:\Users\rabar\Downloads\Firefox.lnk 2022-01-21 17:13 - 2021-06-04 07:58 - 001741820 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2022-01-21 17:13 - 2019-12-07 11:53 - 000752392 _____ C:\WINDOWS\system32\prfh0416.dat 2022-01-21 17:13 - 2019-12-07 11:53 - 000148506 _____ C:\WINDOWS\system32\prfc0416.dat 2022-01-21 17:13 - 2019-12-07 06:13 - 000000000 ____D C:\WINDOWS\INF 2022-01-21 17:06 - 2021-06-04 08:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2022-01-21 17:06 - 2021-06-04 07:54 - 000008192 ___SH C:\DumpStack.log.tmp 2022-01-21 17:06 - 2021-06-04 07:54 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2022-01-21 17:06 - 2020-01-11 13:14 - 000000000 ____D C:\Users\Public\Speedup Sessions 2022-01-20 22:47 - 2021-06-04 08:01 - 000003590 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2022-01-20 22:47 - 2021-06-04 08:01 - 000003466 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2022-01-20 17:26 - 2020-03-08 16:56 - 000000762 _____ C:\Users\rabar\Downloads\del_bone.lnk 2022-01-20 17:16 - 2021-06-16 20:38 - 000000000 ____D C:\Users\rabar\AppData\Local\CrashDumps 2022-01-20 16:57 - 2021-11-23 05:25 - 000000000 ___RD C:\Users\ligia\OneDrive 2022-01-20 11:01 - 2021-11-23 05:25 - 000000000 ____D C:\Users\ligia\AppData\LocalLow\Mozilla 2022-01-20 09:48 - 2020-01-11 06:46 - 000000000 ____D C:\ProgramData\Mozilla 2022-01-20 09:47 - 2021-11-23 05:25 - 000003364 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-652207974-1608278505-3514412468-1006 2022-01-20 09:47 - 2021-11-23 05:24 - 000002385 _____ C:\Users\ligia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2022-01-20 05:53 - 2019-12-07 06:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2022-01-20 05:50 - 2020-01-11 08:35 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2022-01-20 05:49 - 2019-12-07 06:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2022-01-19 03:57 - 2021-07-01 17:44 - 000003524 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d75930c8c1459d 2022-01-19 03:57 - 2021-06-04 08:01 - 000003618 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2022-01-17 18:09 - 2020-01-11 06:32 - 000000000 ____D C:\Users\rabar\AppData\Local\Packages 2022-01-17 17:55 - 2020-01-11 06:46 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2022-01-15 11:04 - 2020-01-11 06:46 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2022-01-14 17:44 - 2019-11-21 00:37 - 000000000 ____D C:\Program Files\Microsoft Office 2022-01-14 05:51 - 2021-06-04 07:54 - 000627440 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2022-01-14 05:50 - 2019-12-07 11:56 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2022-01-14 05:50 - 2019-12-07 06:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2022-01-14 05:50 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2022-01-14 05:50 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SystemResources 2022-01-14 05:50 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\setup 2022-01-14 05:50 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2022-01-14 05:50 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2022-01-14 05:50 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2022-01-14 00:39 - 2019-12-07 06:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2022-01-14 00:22 - 2020-01-11 09:32 - 000000000 ____D C:\WINDOWS\system32\MRT 2022-01-14 00:19 - 2020-01-11 09:32 - 145765912 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2022-01-13 18:43 - 2021-06-04 08:01 - 000003776 _____ C:\WINDOWS\system32\Tasks\AviraSystemSpeedupUpdate 2022-01-11 05:24 - 2021-04-08 15:14 - 000000000 ____D C:\Users\rabar\Desktop\CLELIA 2022-01-10 22:48 - 2020-01-11 07:15 - 000002297 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2022-01-10 22:48 - 2020-01-11 07:15 - 000002256 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2022-01-06 18:06 - 2021-06-04 08:01 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2022-01-04 04:56 - 2020-01-11 11:09 - 000000000 ____D C:\Program Files (x86)\Steam 2021-12-31 20:08 - 2021-06-12 13:19 - 000000000 ____D C:\Users\rabar\AppData\Roaming\.tlauncher 2021-12-31 18:29 - 2020-06-11 21:27 - 000000000 ____D C:\Users\rabar\AppData\Roaming\.minecraft 2021-12-31 14:50 - 2021-01-01 06:58 - 000000743 _____ C:\Users\rabar\Desktop\Minecraft.lnk 2021-12-29 15:47 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\NDF 2021-12-29 15:41 - 2020-04-08 11:53 - 000001134 _____ C:\Users\rabar\Desktop\OpenVPN GUI.lnk 2021-12-27 23:06 - 2020-01-11 06:35 - 000000000 ____D C:\Users\rabar\AppData\Local\D3DSCache ==================== Arquivos na raiz de alguns diretórios ======== 2020-01-11 11:21 - 2020-01-19 14:55 - 000007604 _____ () C:\Users\rabar\AppData\Local\resmon.resmoncfg ==================== SigCheck ============================ (Não há correção automática para arquivos que não passaram na verificação.) ==================== Fim de FRST.txt ========================