Resultado do análise da Farbar Recovery Scan Tool (FRST) (x64) Versão: 31-10-2022 02 Executado por CLIENTE (administrador) em AMILCAR-PC (03-11-2022 14:33:19) Executando a partir de C:\Users\CLIENTE\Desktop Perfis Carregados: CLIENTE Plataforma: Microsoft Windows 10 Pro Versão 21H2 19044.2130 (X64) Idioma: Português (Brasil) Navegador padrão: Chrome Modo da Inicialização: Normal ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe (C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avpui.exe (C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe (C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe (cmd.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (services.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\2.00.36\AsusFanControlService.exe (services.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_c984e9ce714075ab\RtkAudUService64.exe (services.exe ->) (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) C:\Program Files\Topaz OFD\Warsaw\core.exe <2> (svchost.exe ->) (Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe (svchost.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\CPUMetricsServer.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe ==================== Registro (Whitelisted) =================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_c984e9ce714075ab\RtkAudUService64.exe [1345104 2021-09-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (Canon Inc. -> CANON INC.) HKLM-x32\...\Run: [F5_SAM_Client] => C:\Program Files (x86)\F5 VPN\f5fpclientW.exe [4567008 2018-01-18] (F5 Networks Inc -> F5 Networks, Inc.) HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [638352 2018-05-17] (Citrix Systems, Inc. -> Citrix Systems, Inc.) HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [407440 2018-05-17] (Citrix Systems, Inc. -> Citrix Systems, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [711328 2022-06-16] (Oracle America, Inc. -> Oracle Corporation) HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" (Nenhum Arquivo) HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (Nenhum Arquivo) HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restrição <==== ATENÇÃO HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restrição <==== ATENÇÃO HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restrição <==== ATENÇÃO HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\65.0.4.0\GoogleDriveFS.exe [52794648 2022-11-03] (Google LLC -> Google, Inc.) HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\65.0.4.0\GoogleDriveFS.exe [52794648 2022-11-03] (Google LLC -> Google, Inc.) HKU\S-1-5-21-655114216-872089826-439558810-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [38789456 2022-10-20] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) HKU\S-1-5-21-655114216-872089826-439558810-1001\...\Run: [kpm.exe] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.1\kpm.exe [520520 2022-07-18] (AO Kaspersky Lab -> AO Kaspersky Lab) HKU\S-1-5-21-655114216-872089826-439558810-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\65.0.4.0\GoogleDriveFS.exe [52794648 2022-11-03] (Google LLC -> Google, Inc.) HKU\S-1-5-21-655114216-872089826-439558810-1001\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [31295832 2022-03-21] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) HKU\S-1-5-21-655114216-872089826-439558810-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [7201488 2022-08-02] (Adobe Inc. -> Adobe Systems Incorporated) HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\65.0.4.0\GoogleDriveFS.exe [52794648 2022-11-03] (Google LLC -> Google, Inc.) HKLM\...\Windows x64\Print Processors\Canon iP7200 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDBA.DLL [30208 2012-04-16] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Windows x64\Print Processors\hpfpp101: C:\Windows\System32\spool\prtprocs\x64\hpfpp101.dll [254464 2009-10-21] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation) HKLM\...\Print\Monitors\Canon BJ Language Monitor iP7200 series: C:\WINDOWS\system32\CNMLMBA.DLL [389120 2012-04-16] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Canon BJNP Port: C:\WINDOWS\system32\CNMN6PPM.DLL [359936 2012-03-28] (CANON INC.) [Arquivo não assinado] HKLM\...\Print\Monitors\hpf3l101.dll: C:\WINDOWS\system32\hpf3l101.dll [138752 2009-10-21] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Company) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\107.0.5304.88\Installer\chrmstp.exe [2022-11-03] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\PLAP Providers: [{0D4C4485-D868-41C6-876A-8AA3F6709BD5}] -> C:\Program Files (x86)\F5 VPN\F5CredProv64.dll [2017-05-24] (F5 Networks Inc -> F5 Networks, Inc.) GroupPolicy: Restrição ? <==== ATENÇÃO Policies: C:\ProgramData\NTUSER.pol: Restrição <==== ATENÇÃO HKLM\SOFTWARE\Policies\Google: Restrição <==== ATENÇÃO ==================== Tarefas Agendadas (Whitelisted) ============ (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) Task: {1252281F-20B6-483F-8F12-101ABE675660} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [954816 2022-08-19] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) Task: {138CF1E7-80E6-4B99-9B53-41F318F4292E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-10-18] (Google Inc -> Google Inc.) Task: {186EF6D8-1B6F-488D-8948-6C10CF8DE567} - System32\Tasks\ASUS\ASUS File Transfer Server Launcher => C:\Program Files (x86)\ASUS\AI Suite III\File Transfer\Wi-Fi GO! AssistTool\File Transfer Server Launcher.exe [1898480 2017-09-19] (ASUSTeK Computer Inc. -> TODO: ) Task: {2D450EDE-74F7-46B4-8301-2DCCE5C69476} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [56768 2022-08-19] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) Task: {2F312CCB-E9A6-4B01-BE8E-9AD3EF59A8A0} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [26968 2022-03-21] (Garmin International, Inc. -> ) Task: {3210D744-FB05-4ECC-AC78-6861A6817165} - System32\Tasks\CCleanerSkipUAC - CLIENTE => C:\Program Files\CCleaner\CCleaner.exe [32472400 2022-10-20] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) Task: {3537873B-7DB3-4D8A-B3B0-A88F0CB3091A} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [66936 2022-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {35A0174B-E7D6-42BF-A14F-36BBA1D30379} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-10-20] (Piriform Software Ltd -> Piriform) Task: {3A01576A-2402-4061-A14F-581FE43848A3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26154960 2022-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {43764DFA-E224-4065-A4AF-73E2781DDEED} - System32\Tasks\ASUS\ASUS DIPAwayMode => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe [1448408 2018-03-14] (ASUSTeK Computer Inc. -> ) Task: {461A4C5F-36DF-435E-B95C-F82FCA8980D8} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [183232 2022-08-19] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) Task: {4B4CDFBF-4845-46E7-B0E5-18B039394A71} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [954816 2022-08-19] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) Task: {5F9456DE-114F-4DC1-A7A8-3581386C7F3F} - System32\Tasks\ASUS\Ez Update => C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe [1462256 2017-05-17] (ASUSTeK Computer Inc. -> ) Task: {76261C86-DF54-44E5-8703-EEAA74ECD1EA} - System32\Tasks\ASUS\GpuFanHelper => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\GpuFanHelper.exe [4417496 2018-03-14] (ASUSTeK Computer Inc. -> TODO: ) Task: {77EF2BF3-8604-4162-972C-6E592D012E26} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4669264 2022-10-20] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "732ade90-2e81-4ebf-8057-858b75449b71" --version "6.05.10110" --silent Task: {7E2AB54F-7546-46BA-B9E8-7E7DAA1A4564} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26154960 2022-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {904B8E0F-BC18-46AA-9BCE-D42429E4AB59} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-10-18] (Google Inc -> Google Inc.) Task: {938FCC8E-92E4-493F-9F17-4842542FFD38} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144312 2022-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {9F3B0297-6A80-4DC0-9BF6-9789CF699DF5} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-655114216-872089826-439558810-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4166528 2022-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {AB163CB3-52A7-4E7F-8F9E-AC2A6A205531} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424 2021-11-17] (Adobe Inc. -> Adobe Inc.) Task: {BF801C29-4312-4DFD-8758-F1C0C90A9D58} - System32\Tasks\StartCNBM => C:\Program Files\AMD\CNext\CNext\cncmd.exe [56768 2022-08-19] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) Task: {C761A358-7928-40E6-AD49-02D36D415E1B} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144312 2022-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {D50D30E6-5866-421E-A8DE-B61B44B8EA44} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4166528 2022-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {DCF13E8E-E8E1-4FB0-A9AA-7A3AF5A38E7C} - System32\Tasks\Ashampoo Driver Updater_Logon => C:\Program Files\Ashampoo\Ashampoo Driver Updater\ashpdu.exe [4180872 2020-11-12] (Ashampoo GmbH & Co. KG -> Ashampoo) Task: {E4BA6D88-35AD-41F8-BC6A-820AC6B94170} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2096088 2018-01-04] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) Task: {EAF86641-B5EF-4B2A-8E66-94F660D3E8A5} - System32\Tasks\Rerun Warsaw's CoreFixer => C:\WINDOWS\TEMP\is-4A6QK.tmp\corefixer.exe /norerun (Nenhum Arquivo) <==== ATENÇÃO Task: {F56E580C-DE31-4093-BF15-0D760C2C4E56} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [291776 2022-08-19] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) Task: {F7866F75-96D2-4258-B0F2-B27DF7A7AD83} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe /from_scheduler:1 (Nenhum Arquivo) Task: {F8376DCC-6E40-4C4A-9B4E-F27E070F2432} - System32\Tasks\ASUS\AsRogAuraGpuDllServer => C:\Program Files (x86)\LightingService\1.00.42\AsRogAuraGpuDllServer.exe [280536 2018-03-29] (ASUSTeK Computer Inc. -> ) Task: {FAD62747-0235-4FB3-9A8E-295F86481DE9} - System32\Tasks\StartAUEP => C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe [679360 2022-08-19] (Advanced Micro Devices Inc. -> AMD) (Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.) Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.) Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.15.1 Tcpip\..\Interfaces\{78757e90-dae2-4836-a003-8278f27e1e52}: [DhcpNameServer] 192.168.15.1 Edge: ======= DownloadDir: C:\Users\CLIENTE\Downloads Edge HomeButtonPage: HKU\S-1-5-21-655114216-872089826-439558810-1001 -> hxxp://www.goolr.com.br/ Edge Extension: (Sem Nome) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [não encontrado (a)] Edge Extension: (Sem Nome) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [não encontrado (a)] Edge Extension: (Sem Nome) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [não encontrado (a)] Edge Extension: (Sem Nome) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [não encontrado (a)] FireFox: ======== FF HKLM\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\FFExt\light_plugin_firefox\addon.xpi => não encontrado (a) FF HKLM-x32\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\FFExt\light_plugin_firefox\addon.xpi => não encontrado (a) FF Plugin: @java.com/DTPlugin,version=11.341.2 -> C:\Program Files\Java\jre1.8.0_341\bin\dtplugin\npDeployJava1.dll [2022-07-24] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.341.2 -> C:\Program Files\Java\jre1.8.0_341\bin\plugin2\npjp2.dll [2022-07-24] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-03] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-08-02] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [Nenhum Arquivo] FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.) [Arquivo não assinado] FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2018-05-17] (Citrix Systems, Inc. -> Citrix Systems, Inc.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-03] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [Nenhum Arquivo] Chrome: ======= CHR DefaultProfile: Profile 1 CHR Profile: C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Guest Profile [2022-10-18] CHR Profile: C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 1 [2022-11-03] CHR Notifications: Profile 1 -> hxxps://app.slack.com; hxxps://boaforma.abril.com.br; hxxps://calendar.google.com; hxxps://clickpetroleoegas.com.br; hxxps://consultorioonline.psicologiaviva.com.br; hxxps://cursos.anbima.com.br; hxxps://drconsulta.com; hxxps://en.softonic.com; hxxps://m.kabum.com.br; hxxps://madras.com.br; hxxps://meet.google.com; hxxps://minhaclaroresidencial.claro.com.br; hxxps://minhanet.net.com.br; hxxps://ndmais.com.br; hxxps://pt-br.facebook.com; hxxps://rededorpoc.webpush.freshchat.com; hxxps://shopee.com.br; hxxps://totvs.desko.com.br; hxxps://williampolo.com.br; hxxps://www.42frases.com.br; hxxps://www.adorocinema.com; hxxps://www.belasmensagens.com.br; hxxps://www.casasbahia.com.br; hxxps://www.claro.com.br; hxxps://www.climatempo.com.br; hxxps://www.clubeextra.com.br; hxxps://www.drogariasaopaulo.com.br; hxxps://www.einstein.br; hxxps://www.extra.com.br; hxxps://www.facebook.com; hxxps://www.fastshop.com.br; hxxps://www.frasesdobem.com.br; hxxps://www.garminstore.com.br; hxxps://www.gympass.com; hxxps://www.jornalcontabil.com.br; hxxps://www.net.com.br; hxxps://www.netflix.com; hxxps://www.netshoes.com.br; hxxps://www.obramax.com.br; hxxps://www.pensador.com; hxxps://www.pinterest.at; hxxps://www.pontofrio.com.br; hxxps://www.tiktok.com; hxxps://www.tuacarreira.com; hxxps://www.youtube.com CHR Extension: (Kaspersky Protection) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2022-08-02] CHR Extension: (Documentos Google off-line) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-11-03] CHR Extension: (Malwarebytes Browser Guard) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2022-10-16] CHR Extension: (Acesso rápido a apps para o Drive (do Google)) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-01-23] CHR Extension: (WFzone Theme Magenta skull chapter 2) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ngknhofohoopognmlfjiempfglepobng [2021-04-18] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-28] CHR Profile: C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 2 [2022-10-18] CHR Extension: (Apresentações) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-06-17] CHR Extension: (Kaspersky Protection) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2021-06-17] CHR Extension: (Planilhas) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-06-17] CHR Extension: (Documentos Google off-line) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-07-26] CHR Extension: (Malwarebytes Browser Guard) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-07-26] CHR Extension: (Acesso rápido a apps para o Drive (do Google)) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-06-17] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-06-17] CHR Extension: (Chrome Media Router) - C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-17] CHR Profile: C:\Users\CLIENTE\AppData\Local\Google\Chrome\User Data\System Profile [2022-10-18] CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm CHR HKU\S-1-5-21-655114216-872089826-439558810-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\CLIENTE\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx CHR HKU\S-1-5-21-655114216-872089826-439558810-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] ==================== Serviços (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-11-17] (Adobe Inc. -> Adobe Inc.) S2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [923656 2022-08-10] (Adobe Inc. -> Adobe Inc.) S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe [382424 2018-01-04] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\2.00.36\AsusFanControlService.exe [2025944 2018-03-07] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) S2 AUEPLauncher; C:\Program Files\AMD\CIM\..\Performance Profile Client\AUEPDU.exe [509888 2022-08-19] (Advanced Micro Devices Inc. -> AMD) R2 AVP21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe [184768 2021-06-03] (Kaspersky Lab JSC -> AO Kaspersky Lab) S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1185616 2022-10-20] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12516280 2022-11-03] (Microsoft Corporation -> Microsoft Corporation) S2 DTSAPO3Service; C:\WINDOWS\System32\DTS\PC\APO3x\DTSAPO3Service.exe [222104 2020-07-16] (DTS, Inc. -> ) S2 F5 Networks Component Installer; C:\WINDOWS\SysWOW64\F5InstallerService.exe [527328 2018-01-18] (F5 Networks Inc -> F5 Networks, Inc.) S2 F5FltSrv; C:\WINDOWS\SysWOW64\F5FltSrv.exe [481248 2018-01-18] (F5 Networks Inc -> F5 Networks, Inc.) S2 F5TrafficSrv; C:\WINDOWS\SysWOW64\F5TrafficSrv.exe [245216 2017-05-24] (F5 Networks Inc -> F5 Networks, Inc.) S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.212.1009.0004\FileSyncHelper.exe [3475328 2022-11-03] (Microsoft Corporation -> Microsoft Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Arquivo não assinado] S4 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] (Canon Inc. -> ) S3 klvssbridge64_21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\x64\vssbridge64.exe [479280 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab) S2 kpm_service_10.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.1\kpm_service.exe [518472 2022-07-18] (AO Kaspersky Lab -> AO Kaspersky Lab) S2 LightingService; C:\Program Files (x86)\LightingService\1.00.42\LightingService.exe [1289688 2018-03-29] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Arquivo não assinado] S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.212.1009.0004\OneDriveUpdaterService.exe [3840896 2022-11-03] (Microsoft Corporation -> Microsoft Corporation) S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Arquivo não assinado] S2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2020-02-21] (Even Balance, Inc. -> ) S2 scpbradserv; C:\Program Files (x86)\scpbrad\scpbradserv.exe [2269056 2021-03-07] (Banco Bradesco S.A. -> Scopus Soluções em TI Ltda) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [224192 2022-09-20] (Microsoft Windows Publisher -> Microsoft Corporation) R2 Warsaw Technology; C:\Program Files\Topaz OFD\Warsaw\core.exe [1004448 2022-04-12] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe [2872024 2021-11-15] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe [128376 2021-11-15] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [35360 2022-06-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) R2 AMDRyzenMasterDriverV19; C:\WINDOWS\system32\AMDRyzenMasterDriver.sys [43336 2022-08-19] (Advanced Micro Devices INC. -> Advanced Micro Devices) R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_66a9fa5d80327844\amdsafd.sys [113080 2022-06-23] (Advanced Micro Devices Inc. -> Advanced Micro Devices) R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0382768.inf_amd64_e7e6a9c747335e93\B382613\amdkmdag.sys [94445064 2022-08-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [59920 2022-05-31] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2017-06-01] (ASUSTeK Computer Inc. -> ) R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2017-03-14] (ASUSTeK Computer Inc. -> ) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Arquivo não assinado] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Arquivo não assinado] R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [237288 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) S3 F5FltDrv; C:\WINDOWS\SysWOW64\drivers\F5FltDrv.sys [47848 2018-01-18] (F5 Networks, Inc. -> F5 Networks, Inc.) S3 f5ipfw; C:\WINDOWS\system32\drivers\urfltv64.sys [34536 2016-06-02] (F5 Networks, Inc. -> F5 Networks, Inc.) R1 googledrivefs3758; C:\WINDOWS\System32\DRIVERS\googledrivefs3758.sys [384584 2022-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2020-05-31] (Martin Malik - REALiX -> REALiX(tm)) R1 klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [105280 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [206600 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [119568 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [41656 2021-02-19] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab) R1 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [522504 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klgse; C:\WINDOWS\System32\DRIVERS\klgse.sys [703056 2022-06-09] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klhk; C:\WINDOWS\system32\DRIVERS\klhk.sys [1586112 2022-08-12] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) S3 klids; C:\ProgramData\Kaspersky Lab\AVP21.3\Bases\klids.sys [189032 2022-09-06] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1049864 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [90896 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [104728 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [107328 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [78088 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [88328 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [382304 2022-09-30] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [360000 2022-09-30] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [189520 2022-09-30] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [270672 2022-09-30] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [150280 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [325400 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [294680 2022-02-01] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) S3 MpKsl325ed7f4; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{85A1183E-E9C9-4D32-9207-060B791903E1}\MpKslDrv.sys [130296 2021-11-20] (Microsoft Windows -> Microsoft Corporation) S3 MpKsl486a6291; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{85A1183E-E9C9-4D32-9207-060B791903E1}\MpKslDrv.sys [130296 2021-11-20] (Microsoft Windows -> Microsoft Corporation) R3 RtsUpx; C:\Windows\system32\drivers\RtsUpx.sys [30328 2019-10-21] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) R3 Serial; C:\WINDOWS\system32\DRIVERS\wdfserial.sys [89976 2018-04-26] (LG Electronics Inc. -> LG Electronics Inc.) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166760 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R3 urvpndrv; C:\WINDOWS\System32\drivers\covpnv64.sys [57736 2018-01-18] (F5 Networks Inc -> F5 Networks, Inc.) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48520 2021-11-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [435424 2021-11-15] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-11-15] (Microsoft Windows -> Microsoft Corporation) R1 wsddfac; C:\WINDOWS\System32\drivers\wsddfac.sys [47800 2022-11-03] (Gas Informatica Ltda -> GAS Tecnologia) R1 wsddntf; C:\WINDOWS\system32\DRIVERS\wsddntf.sys [51160 2021-02-11] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) R1 wsddpp; C:\WINDOWS\system32\drivers\wsddpp.sys [34768 2021-02-11] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) R3 wsddprm; C:\WINDOWS\system32\drivers\wsddprm.sys [36768 2022-02-25] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) S2 AMDRyzenMasterDriverV17; \??\C:\Program Files\AMD\CNext\CNext\AMDRyzenMasterDriver.sys [X] ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um mês (criados) (Whitelisted) ========= (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2022-11-03 14:33 - 2022-11-03 14:33 - 000035301 _____ C:\Users\CLIENTE\Desktop\FRST.txt 2022-11-03 14:33 - 2022-11-03 14:33 - 000000000 ____D C:\FRST 2022-11-03 14:30 - 2022-11-03 14:31 - 000000000 ____D C:\AdwCleaner 2022-11-03 11:23 - 2022-11-03 11:23 - 002374144 _____ (Farbar) C:\Users\CLIENTE\Desktop\FRST64.exe 2022-11-03 11:22 - 2022-11-03 11:22 - 008791352 _____ (Malwarebytes) C:\Users\CLIENTE\Desktop\adwcleaner.exe 2022-10-18 11:56 - 2022-10-18 11:57 - 114442240 _____ C:\Users\CLIENTE\Downloads\aplicativoitau.msi 2022-10-18 11:43 - 2022-10-18 11:43 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll 2022-10-18 11:43 - 2022-10-18 11:43 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2022-10-18 11:43 - 2022-10-18 11:43 - 000012253 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2022-10-18 11:42 - 2022-10-18 11:42 - 002260480 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll 2022-10-18 11:42 - 2022-10-18 11:42 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll 2022-10-18 11:42 - 2022-10-18 11:42 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe 2022-10-18 11:42 - 2022-10-18 11:42 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2022-10-18 11:35 - 2022-10-18 11:35 - 000000000 ___HD C:\$WinREAgent 2022-10-16 22:48 - 2022-10-16 22:48 - 000000000 ____D C:\Users\CLIENTE\Downloads\Telegram Desktop 2022-10-05 18:53 - 2022-10-05 18:53 - 000643279 _____ C:\Users\CLIENTE\Downloads\637994663358868717.pdf 2022-10-05 16:00 - 2022-10-05 16:00 - 000000000 ____D C:\Users\CLIENTE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom 2022-10-05 12:22 - 2022-10-05 12:22 - 000000000 ____D C:\Users\Public\Documents\AdobeGCInfo 2022-10-05 10:40 - 2022-10-05 10:40 - 002861336 _____ (Adobe Inc.) C:\Users\CLIENTE\Downloads\Creative_Cloud_Set-Up.exe ==================== Um mês (modificados) ================== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2022-11-03 14:31 - 2019-12-07 06:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2022-11-03 14:29 - 2021-06-17 23:36 - 000002474 _____ C:\Users\CLIENTE\Desktop\Pessoa 2 - Chrome.lnk 2022-11-03 14:28 - 2020-09-24 23:47 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2022-11-03 13:51 - 2019-10-18 23:57 - 000000000 ____D C:\Program Files (x86)\Google 2022-11-03 11:32 - 2019-12-07 06:14 - 000000000 ___HD C:\Program Files\WindowsApps 2022-11-03 11:32 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2022-11-03 11:18 - 2019-10-21 13:08 - 000000000 ____D C:\ProgramData\Oracle 2022-11-03 10:26 - 2022-09-20 15:59 - 000003470 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting 2022-11-03 10:26 - 2022-09-20 15:59 - 000000760 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job 2022-11-03 10:26 - 2020-09-24 23:54 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2022-11-03 10:26 - 2019-10-19 14:11 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk 2022-11-03 10:26 - 2019-10-19 14:11 - 000000000 ____D C:\Program Files\CCleaner 2022-11-03 09:53 - 2022-09-02 17:12 - 000000000 ____D C:\Program Files\Microsoft Office 2022-11-03 09:50 - 2019-10-18 23:54 - 000000000 ____D C:\AMD 2022-11-03 09:49 - 2021-01-04 21:43 - 000000000 ____D C:\Users\CLIENTE\AppData\Local\AMD_Common 2022-11-03 09:48 - 2019-12-07 06:13 - 000000000 ____D C:\WINDOWS\INF 2022-11-03 09:47 - 2020-10-30 21:30 - 000004182 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{C497E428-6753-45AF-8F66-A5EAA381F9CD} 2022-11-03 09:46 - 2022-09-02 18:38 - 000000000 ____D C:\Program Files\Microsoft OneDrive 2022-11-03 09:46 - 2022-09-02 17:14 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-655114216-872089826-439558810-1001 2022-11-03 09:46 - 2022-09-02 17:14 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task 2022-11-03 09:46 - 2022-09-02 17:14 - 000002138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2022-11-03 09:45 - 2019-10-18 23:57 - 000002299 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2022-11-03 09:45 - 2019-10-18 23:57 - 000002258 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2022-11-03 09:44 - 2021-02-01 17:34 - 000002057 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk 2022-11-03 09:44 - 2020-02-25 14:08 - 000001863 _____ C:\Users\CLIENTE\Desktop\Google Drive.lnk 2022-11-03 09:43 - 2020-04-26 19:22 - 000047800 _____ (GAS Tecnologia) C:\WINDOWS\system32\Drivers\wsddfac.sys 2022-10-18 13:06 - 2020-09-24 23:52 - 001741824 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2022-10-18 13:06 - 2019-12-07 11:53 - 000752436 _____ C:\WINDOWS\system32\prfh0416.dat 2022-10-18 13:06 - 2019-12-07 11:53 - 000148550 _____ C:\WINDOWS\system32\prfc0416.dat 2022-10-18 13:01 - 2020-09-24 23:54 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2022-10-18 13:01 - 2020-09-24 23:47 - 000454816 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2022-10-18 13:01 - 2020-09-24 23:47 - 000008192 ___SH C:\DumpStack.log.tmp 2022-10-18 13:01 - 2019-12-07 06:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2022-10-18 13:01 - 2019-12-07 06:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2022-10-18 13:01 - 2019-10-18 23:54 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin 2022-10-18 13:00 - 2019-12-07 11:56 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2022-10-18 13:00 - 2019-12-07 06:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2022-10-18 13:00 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2022-10-18 13:00 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SystemResources 2022-10-18 13:00 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2022-10-18 13:00 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2022-10-18 13:00 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2022-10-18 13:00 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\Provisioning 2022-10-18 13:00 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2022-10-18 13:00 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2022-10-18 12:53 - 2020-05-12 22:35 - 000000000 ____D C:\Users\CLIENTE\AppData\Local\Citrix 2022-10-18 11:45 - 2019-12-07 06:15 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll 2022-10-18 11:45 - 2019-12-07 06:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll 2022-10-18 11:45 - 2019-12-07 06:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2022-10-18 11:42 - 2020-09-24 23:51 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2022-10-18 09:21 - 2019-10-20 20:21 - 000000000 ____D C:\WINDOWS\system32\MRT 2022-10-18 09:18 - 2019-10-20 20:21 - 147398024 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2022-10-16 23:17 - 2021-04-12 20:24 - 000001038 _____ C:\Users\CLIENTE\Desktop\Telegram.lnk 2022-10-16 23:17 - 2021-04-12 20:24 - 000000000 ____D C:\Users\CLIENTE\AppData\Roaming\Telegram Desktop 2022-10-16 23:17 - 2021-04-12 20:24 - 000000000 ____D C:\Users\CLIENTE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop 2022-10-16 22:44 - 2022-07-18 11:51 - 000083088 _____ C:\Users\CLIENTE\Documents\MEGA-SENA_CONFERIDOR.xlsx 2022-10-16 22:36 - 2022-09-20 11:33 - 000003750 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{7D5FBDCE-5299-46FF-8DFC-8FCE09B0ED8C} 2022-10-16 22:36 - 2022-09-20 11:33 - 000003626 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{F7C25AC6-904A-4E40-83C9-549BEF3CD21B} 2022-10-05 16:16 - 2022-01-13 09:48 - 000000000 ____D C:\Users\CLIENTE\Documents\___________________________PLANILHAS 2022-10-05 16:16 - 2020-05-05 23:20 - 000000000 ____D C:\Users\CLIENTE\Documents\Zoom 2022-10-05 16:00 - 2021-06-25 11:21 - 000001937 _____ C:\Users\CLIENTE\Desktop\Zoom.lnk 2022-10-05 16:00 - 2020-05-05 23:17 - 000000000 ____D C:\Users\CLIENTE\AppData\Roaming\Zoom 2022-10-05 12:03 - 2021-02-22 14:09 - 000000000 ____D C:\temp ==================== Arquivos na raiz de alguns diretórios ======== 2019-10-19 14:49 - 2022-10-05 12:22 - 000000615 _____ () C:\Users\CLIENTE\AppData\Local\oobelibMkey.log ==================== SigCheck ============================ (Não há correção automática para arquivos que não passaram na verificação.) ==================== Fim de FRST.txt ========================