Logo Hardware.com.br

Análise de log, remoção de vírus, arquivos nocivos

Sala destinada para questões, dúvidas e dicas envolvendo análise de log e remoções: como analisar um log, ferramentas e procedimentos necessários no auxílio para remoção de arquivos nocivos (vírus, spywares, malwares, trojans etc.).

4
7
locked locked

Problemas com vírus? Saiba como criar um tópico para análise.

83adb5d479489f1a6e586e351176d6f2


Farbar Recovery Scan Tool



observe.png Baixe o Farbar Recovery Scan Tool e salve-o no Desktop (Área de Trabalho)

*Usuários dos Windows Vista / 7 / 8 verifiquem se o sistema é 32 ou 64 bit e façam o download da versão correta.

*Usuários do Windows XP devem fazer o download da versão 32 bit.

*Execute o FRST e aceite o contrato

[center]08cdb4bf863e4282faad98841c0496ae

* Marcar a caixa [Arquivos 90 Dias]
* E clique [Examinar]

Anexo do post


*Ao término clique [OK] > [OK]

a5e4d32110076f272e7ba5e25f0752fd


adb6035b9e6ade6cc34ad5bbe953090e


*Serão criados dois relatórios no Desktop: FRST.txt e Addition.txt


veja.pngAcesse este link

*Clique [Selecionar arquivo...], localize o relatório FRST.txt e clique [Abrir]

*Selecione 4 jours e clique [Créer le lien Cjoint]

fb405a606703ea7bf37880bb8770d9e7


*Cole o link criado ao lado de Le lien a été créé:

cae86b35b8d8683484b25434c8be7fc9


*Repita o procedimento para o relatório Addition.txt e cole o link



policia.gif
Tópico atualizado a pedido de "joram"
0

dism error RestoreHealth 0x800f081f (win 11 23h2 22631.4169)

olá,

Se o post estiver no local errado, favor mover para o local correto.

Executo o SFC em "modo normal" e o "modo de segurança", ambos como nivel administrador, nenhum arquivo corrompido foi encontrado.

Executo o comando:
dism.exe /online /Cleanup-Image /RestoreHealth


no modo adm CMD para restaurar o sistema atual, mas recebo esta mensagem "erro 0x800f081f Os arquivos de origem não foram encontrados".

Executo o comando:
dism.exe /Online /Cleanup-Image /RestoreHealth /Fonte:WIM:D:\install.wim:4 /LimitAccess


no modo adm CMD para restaurar o sistema atual de outra fonte, mas recebo esta mensagem "erro 0x800f081f Os arquivos de origem não foram encontrados".

Executei o SFCFix  sem erros.. 

Meu sistema reinicia aleatoriamente quando eu uso, como posso consertar?

os LOGs estão em anexo.
0

Paranóia ou Espião

Olá!
Primeira vez aqui, então desculpem caso poste de forma errada!
Não sei se sou paranoico. Mas em certos momentos meu computador passa a ficar lento, com a ventoinha ligando, e percebo comportamentos estranhos. Há interferência entre o computador e o celular (não há sincronização entre ambos), há alterações de software (desinstalações automáticas).

Estou usando uma rede Wifi em casa (modem NET + Extensor de sinal) com minha família.

Só a título de exemplo, consultei um dos "Eventos" do Visualizador de Eventos de hoje mesmo, quando minha esposa (confused.png) chegou em casa (próx. do horário)

Nome do Log:   Microsoft-Windows-WLAN-AutoConfig/Operational
Fonte:         Microsoft-Windows-WLAN-AutoConfig
Data:          13/08/2024 13:38:35
Identificação do Evento:11010
Categoria da Tarefa:MsmSecurity
Nível:         Informações
Palavras-chave1024),(512)
Usuário:       SISTEMA
Computador:    OFFLINE
Descrição:
Segurança sem fio iniciada.

Adaptador de Rede: Intel(R) Wireless-AC 9560
GUID de Interface: {ef6d8af2-e5cf-40ed-9ff9-e004b20a8d4d}
Endereço MAC Local: AC:82:47:94:11:41
SSID de Rede: AP111
Tipo de BSS: Infrastructure
Autenticação: WPA2-Personal
Criptografia: AES-CCMP
Modo FIPS: Disabled
Habilitado para 802.1x: No

XML de Evento:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-WLAN-AutoConfig" Guid="{9580d7dd-0379-4658-9870-d5be7d52d6de}" />
    <EventID>11010</EventID>
    <Version>0</Version>
    <Level>4</Level>
    <Task>24012</Task>
    <Opcode>200</Opcode>
    <Keywords>0x8000000000000600</Keywords>
    <TimeCreated SystemTime="2024-08-13T16:38:35.5415830Z" />
    <EventRecordID>443</EventRecordID>
    <Correlation />
    <Execution ProcessID="3552" ThreadID="12564" />
    <Channel>Microsoft-Windows-WLAN-AutoConfig/Operational</Channel>
    <Computer>OFFLINE</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="Adapter">Intel(R) Wireless-AC 9560</Data>
    <Data Name="DeviceGuid">{ef6d8af2-e5cf-40ed-9ff9-e004b20a8d4d}</Data>
    <Data Name="LocalMac">AC:82:47:94:11:41</Data>
    <Data Name="SSID">AP111</Data>
    <Data Name="BSSType">Infrastructure</Data>
    <Data Name="Auth">WPA2-Personal</Data>
    <Data Name="AuthVal">7</Data>
    <Data Name="Cipher">AES-CCMP</Data>
    <Data Name="CipherVal">4</Data>
    <Data Name="FIPSMode">0</Data>
    <Data Name="OnexEnabled">0</Data>
    <Data Name="ConnectionId">0x1</Data>
  </EventData>
</Event>


Sei que pode não ser nada.
ONTEM eu fiz os procedimentos de análise que eu vi vocês pedindo em outros tópicos (Obs: Não tenho mais Echo Dot, Alexa, nem nada):
Esse é o "Addition.txt"

Resultado da análise adicional Farbar Recovery Scan Tool (x64) Versão: 12-08.2024
Executado por Raphael (12-08-2024 17:58:16)
Executando a partir de C:\Users\Raphael\Downloads
Microsoft Windows 10 Home Single Language Versão 22H2 19045.4651 (X64) (2024-08-09 18:51:03)
Modo da Inicialização: Normal
==========================================================


==================== Contas: =============================


(Se uma entrada for incluída na fixlist, será removida.)

Administrador (S-1-5-21-1147774137-2360836381-337630343-500 - Administrator - Disabled)
alexa (S-1-5-21-1147774137-2360836381-337630343-1003 - Limited - Disabled)
Convidado (S-1-5-21-1147774137-2360836381-337630343-501 - Limited - Disabled)
DefaultAccount (S-1-5-21-1147774137-2360836381-337630343-503 - Limited - Disabled)
rapha (S-1-5-21-1147774137-2360836381-337630343-1002 - Limited - Disabled)
Raphael (S-1-5-21-1147774137-2360836381-337630343-1001 - Administrator - Enabled) => C:\Users\Raphael
WDAGUtilityAccount (S-1-5-21-1147774137-2360836381-337630343-504 - Limited - Disabled)

==================== Central de Segurança ========================

(Se uma entrada for incluída na fixlist, será removida.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas Instalados ======================

(Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.)

7-Zip 24.07 (x64) (HKLM\...\7-Zip) (Version: 24.07 - Igor Pavlov)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1046-1033-7760-BC15014EA700}) (Version: 24.002.20991 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601091}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AnyDesk (HKLM-x32\...\AnyDesk) (Version: ad 8.0.12 - AnyDesk Software GmbH)
Google Chrome (HKLM\...\{E3F24F22-6113-339A-BFD2-049E083FAA33}) (Version: 127.0.6533.100 - Google LLC)
Java 8 Update 421 (HKLM-x32\...\{77924AE4-039E-4CA4-87B4-2F32180421F0}) (Version: 8.0.4210.9 - Oracle Corporation)
Lenovo Service Bridge (HKU\S-1-5-21-1147774137-2360836381-337630343-1001\...\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1) (Version: 5.0.2.17 - Lenovo)
Lenovo System Update (HKLM-x32\...\TVSU_is1) (Version: 5.08.03.59 - Lenovo)
Microsoft 365 - pt-br (HKLM\...\O365HomePremRetail - pt-br) (Version: 16.0.17830.20138 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 127.0.2651.98 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 126.0.2592.113 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 24.151.0728.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 (HKLM-x32\...\{7474cd6e-76cc-4257-837e-5b9261e526af}) (Version: 14.13.26020.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.13.26020 (HKLM-x32\...\{5c045b7f-e561-4794-91f8-c6cda0893107}) (Version: 14.13.26020.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 x64 Additional Runtime - 14.13.26020 (HKLM\...\{C5ECDB9A-D9B0-3107-BA85-1269998A5B3E}) (Version: 14.13.26020 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2017 x64 Minimum Runtime - 14.13.26020 (HKLM\...\{221D6DB4-46E2-333C-B09B-5F49351D0980}) (Version: 14.13.26020 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2017 x86 Additional Runtime - 14.13.26020 (HKLM-x32\...\{895D5198-C5DB-375E-86AB-133F4DAA9FE2}) (Version: 14.13.26020 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.13.26020 (HKLM-x32\...\{8F271F6C-6E7B-3D0A-951B-6E7B694D78BD}) (Version: 14.13.26020 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 pt-BR) (HKLM\...\Mozilla Firefox 129.0 (x64 pt-BR)) (Version: 129.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 129.0 - Mozilla)
NVIDIA Driver de gráficos 462.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 462.30 - NVIDIA Corporation)
NVIDIA FrameView SDK 1.1.4923.29548709 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.1.4923.29548709 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.21.0.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.21.0.36 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.17830.20138 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.17830.20138 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0416-1000-0000000FF1CE}) (Version: 16.0.17628.20110 - Microsoft Corporation) Hidden
Revo Uninstaller 2.4.5 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.4.5 - VS Revo Group, Ltd.)
SafeNet Authentication Client 10.6 (HKLM\...\{89055E78-5D23-42F0-85F2-935CC03FA229}) (Version: 10.6.115.0 - Gemalto)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{85C69797-7336-4E83-8D97-32A7C8465A3B}) (Version: 8.94.0.0 - Microsoft Corporation)
Web PKI (HKLM-x32\...\{871C6B2B-B806-9D07-58C1-09F88DEC66F1}) (Version: 2.12.3.0 - Lacuna Software)
WebSigner Extension (HKLM-x32\...\{193EB203-846D-FB51-B1D6-31E017F0D344}) (Version: 2.9.0.1 - Certisign)

Packages:
=========

Centro de comando de gráficos Intel® -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5587.0_x64__8j3eq9eme6ctt [2024-08-09] (INTEL CORP) [Startup Task]
Dolby Audio -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAudio_3.20602.609.0_x64__rz1tebttyb220 [2024-08-09] (Dolby Laboratories)
Email e Calendário -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe [2024-08-09] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2024-08-09] (Microsoft Corporation) [MS Ad]
Microsoft Defender -> C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2407.18001.0_x64__8wekyb3d8bbwe [2024-08-12] (Microsoft Corporation) [Startup Task]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.8204.0_x64__8wekyb3d8bbwe [2024-08-09] (Microsoft Studios) [MS Ad]
Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_53.21110.548.0_x64__8wekyb3d8bbwe [2024-08-11] (Microsoft Corporation)
MSN Clima -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.25.20211.0_x64__8wekyb3d8bbwe [2024-08-09] (Microsoft Corporation) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.966.0_x64__56jybvy8sckqj [2024-08-09] (NVIDIA Corp.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2024-08-09] (Realtek Semiconductor Corp)
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.77.0_x64__kzf8qxf38zg5c [2024-08-09] (Skype)

==================== Análise Personalizada CLSID (Whitelisted): ==============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

CustomCLSID: HKU\S-1-5-21-1147774137-2360836381-337630343-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-1147774137-2360836381-337630343-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-06-19] (Igor Pavlov) [Arquivo não assinado]
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-06-19] (Igor Pavlov) [Arquivo não assinado]
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncShell64.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_5adc6075318430cf\nvshext.dll [2021-08-31] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-06-19] (Igor Pavlov) [Arquivo não assinado]

==================== Codecs (Whitelisted) ====================

==================== Atalhos & WMI ========================

==================== Módulos Carregados (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Modo de Segurança (Whitelisted) ==================

==================== Associação (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_421\bin\ssv.dll [2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_421\bin\jp2ssv.dll [2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts Conteúdo: =========================

(Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.)

2019-12-07 06:14 - 2019-12-07 06:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

==================== Outras Áreas ===========================

(Atualmente não há nenhuma correção automática para esta seção.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\java8path;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files\SafeNet\Authentication\SAC\x64;C:\Program Files\SafeNet\Authentication\SAC\x32
HKU\S-1-5-21-1147774137-2360836381-337630343-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 181.213.132.2 - 181.213.132.3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Firewall do Windows está habilitado.

Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
Wi-Fi: Intel(R) Wireless-AC 9560 -> Netwtw10.sys


==================== MSCONFIG/TASK MANAGER ítens desabilitados ==

(Se uma entrada for incluída na fixlist, será removida.)

HKLM\...\StartupApproved\StartupFolder: => "AnyDesk.lnk"
HKU\S-1-5-21-1147774137-2360836381-337630343-1001\...\StartupApproved\Run: => "OneDriveSetup"

==================== Regras do Firewall (Whitelisted) ================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

FirewallRules: [{D9770AA3-2B50-4C02-81BD-98AF03489B84}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [{943FB97D-F082-4A68-9467-6A204F482D97}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [{E01B6931-F07B-495B-915F-1D2E552A1230}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [{271090C1-5133-46B9-B8DD-AAF330262D15}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [{A5BB600D-9BDC-4E61-B039-184AE81F867C}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [{415EED9A-57F3-4048-912E-1D6B72AB212C}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [{5081D27C-8359-478B-B546-6F7A14CCA5AB}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> Lenovo)
FirewallRules: [{65F9A46C-7742-425C-A008-E697323E1D61}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> Lenovo)

==================== Pontos de Restauração =========================

11-08-2024 19:26:46 Instalador de Módulos do Windows
12-08-2024 13:26:13 Installed WebSigner Extension
12-08-2024 15:14:37 Instalador de Módulos do Windows
12-08-2024 15:14:57 Instalador de Módulos do Windows

==================== Dispositivos Apresentando Falhas No Gerenciador ============


==================== Erros no Log de eventos: ========================

Erros em Aplicativos:
==================
Error: (08/12/2024 02:10:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: TPMProvisioningService.exe, versão: 1.62.321.1, carimbo de data/hora: 0x5f633888
Nome do módulo com falha: ntdll.dll, versão: 10.0.19041.4522, carimbo de data/hora: 0x8a1bb6f3
Código de exceção: 0xc0000409
Deslocamento da falha: 0x000000000008cc5f
ID do processo com falha: 0x11ac
Hora de início do aplicativo com falha: 0x01daecda7ff26cb9
Caminho do aplicativo com falha: C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe
Caminho do módulo com falha: C:\Windows\SYSTEM32\ntdll.dll
ID do Relatório: ed06bb6f-aa05-4fc5-9e9e-c91a68ee45b2
Nome completo do pacote com falha:
ID do aplicativo relativo ao pacote com falha:

Error: (08/12/2024 12:35:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: PeopleApp.exe, versão: 10.1902.1903.4003, carimbo de data/hora: 0x5c7e161f
Nome do módulo com falha: KERNELBASE.dll, versão: 10.0.19041.4648, carimbo de data/hora: 0x5a4af933
Código de exceção: 0xc000027b
Deslocamento da falha: 0x000000000012d5d2
ID do processo com falha: 0xd3c
Hora de início do aplicativo com falha: 0x01daeccd510ce66f
Caminho do aplicativo com falha: C:\Program Files\WindowsApps\Microsoft.People_10.1902.633.0_x64__8wekyb3d8bbwe\PeopleApp.exe
Caminho do módulo com falha: C:\Windows\System32\KERNELBASE.dll
ID do Relatório: eaf760e6-f3a1-4379-ac55-eeab95f4873d
Nome completo do pacote com falha: Microsoft.People_10.1902.633.0_x64__8wekyb3d8bbwe
ID do aplicativo relativo ao pacote com falha: x4c7a3b7dy2188y46d4ya362y19ac5a5805e5x

Error: (08/12/2024 11:21:06 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: PeopleApp.exe, versão: 10.1902.1903.4003, carimbo de data/hora: 0x5c7e161f
Nome do módulo com falha: KERNELBASE.dll, versão: 10.0.19041.4648, carimbo de data/hora: 0x5a4af933
Código de exceção: 0xc000027b
Deslocamento da falha: 0x000000000012d5d2
ID do processo com falha: 0x734
Hora de início do aplicativo com falha: 0x01daecc2dcd70412
Caminho do aplicativo com falha: C:\Program Files\WindowsApps\Microsoft.People_10.1902.633.0_x64__8wekyb3d8bbwe\PeopleApp.exe
Caminho do módulo com falha: C:\Windows\System32\KERNELBASE.dll
ID do Relatório: 271e3d7d-c66e-4ea3-aef2-deb26746fe38
Nome completo do pacote com falha: Microsoft.People_10.1902.633.0_x64__8wekyb3d8bbwe
ID do aplicativo relativo ao pacote com falha: x4c7a3b7dy2188y46d4ya362y19ac5a5805e5x

Error: (08/12/2024 11:19:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: TPMProvisioningService.exe, versão: 1.62.321.1, carimbo de data/hora: 0x5f633888
Nome do módulo com falha: ntdll.dll, versão: 10.0.19041.4522, carimbo de data/hora: 0x8a1bb6f3
Código de exceção: 0xc0000409
Deslocamento da falha: 0x000000000008cc5f
ID do processo com falha: 0x1230
Hora de início do aplicativo com falha: 0x01daecc2ac3f3dd0
Caminho do aplicativo com falha: C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe
Caminho do módulo com falha: C:\Windows\SYSTEM32\ntdll.dll
ID do Relatório: e8eb55ce-c856-40d0-9ccf-0da443827629
Nome completo do pacote com falha:
ID do aplicativo relativo ao pacote com falha:

Error: (08/09/2024 11:50:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: TPMProvisioningService.exe, versão: 1.62.321.1, carimbo de data/hora: 0x5f633888
Nome do módulo com falha: ntdll.dll, versão: 10.0.19041.4522, carimbo de data/hora: 0x8a1bb6f3
Código de exceção: 0xc0000409
Deslocamento da falha: 0x000000000008cc5f
ID do processo com falha: 0x109c
Hora de início do aplicativo com falha: 0x01daead013418ae3
Caminho do aplicativo com falha: C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\TPMProvisioningService.exe
Caminho do módulo com falha: C:\Windows\SYSTEM32\ntdll.dll
ID do Relatório: 8b1f56ea-9e1c-4763-8b33-cfc67296ed83
Nome completo do pacote com falha:
ID do aplicativo relativo ao pacote com falha:

Error: (08/09/2024 11:50:14 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informações sobre o Serviço de Cópias de Sombra de Volume: não é possível iniciar o Servidor COM com CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} e nome CEventSystem. [0x8007045b, O sistema está sendo desligado.]

Error: (08/09/2024 08:15:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: PeopleApp.exe, versão: 10.1902.1903.4003, carimbo de data/hora: 0x5c7e161f
Nome do módulo com falha: KERNELBASE.dll, versão: 10.0.19041.3758, carimbo de data/hora: 0xd80f8f12
Código de exceção: 0xc000027b
Deslocamento da falha: 0x000000000012db22
ID do processo com falha: 0x4a0
Hora de início do aplicativo com falha: 0x01daeab05ee0d02f
Caminho do aplicativo com falha: C:\Program Files\WindowsApps\Microsoft.People_10.1902.633.0_x64__8wekyb3d8bbwe\PeopleApp.exe
Caminho do módulo com falha: C:\Windows\System32\KERNELBASE.dll
ID do Relatório: 94b6c44a-d0a6-4d82-85f1-e262bfe7ce20
Nome completo do pacote com falha: Microsoft.People_10.1902.633.0_x64__8wekyb3d8bbwe
ID do aplicativo relativo ao pacote com falha: x4c7a3b7dy2188y46d4ya362y19ac5a5805e5x

Error: (08/09/2024 08:00:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: PeopleApp.exe, versão: 10.1902.1903.4003, carimbo de data/hora: 0x5c7e161f
Nome do módulo com falha: KERNELBASE.dll, versão: 10.0.19041.3758, carimbo de data/hora: 0xd80f8f12
Código de exceção: 0xc000027b
Deslocamento da falha: 0x000000000012db22
ID do processo com falha: 0x7bc
Hora de início do aplicativo com falha: 0x01daeaafe1c4ff6b
Caminho do aplicativo com falha: C:\Program Files\WindowsApps\Microsoft.People_10.1902.633.0_x64__8wekyb3d8bbwe\PeopleApp.exe
Caminho do módulo com falha: C:\Windows\System32\KERNELBASE.dll
ID do Relatório: 7a859ecf-616f-4c80-b7ed-774a0eb93ffd
Nome completo do pacote com falha: Microsoft.People_10.1902.633.0_x64__8wekyb3d8bbwe
ID do aplicativo relativo ao pacote com falha: x4c7a3b7dy2188y46d4ya362y19ac5a5805e5x


Erros de Sistema:
=============
Error: (08/12/2024 02:10:17 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: AUTORIDADE NT)
Description: A atualização de Inicialização Segura falhou ao atualizar uma variável de Inicialização Segura com o erro -2147020471. Para mais informações, consulte https://go.microsoft.com/fwlink/?linkid=2169931

Error: (08/12/2024 02:10:16 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: O serviço Intel(R) TPM Provisioning Service foi encerrado inesperadamente.  Isso aconteceu 1 vez(es).

Error: (08/12/2024 02:09:42 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-RCI3PGE)
Description: O servidor {021E4F06-9DCC-49AD-88CF-ECC2DA314C8A} não se registrou no DCOM dentro do tempo limite necessário.

Error: (08/12/2024 02:09:42 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-RCI3PGE)
Description: O servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} não se registrou no DCOM dentro do tempo limite necessário.

Error: (08/12/2024 02:09:42 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-RCI3PGE)
Description: O servidor {021E4F06-9DCC-49AD-88CF-ECC2DA314C8A} não se registrou no DCOM dentro do tempo limite necessário.

Error: (08/12/2024 02:09:42 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-RCI3PGE)
Description: O servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} não se registrou no DCOM dentro do tempo limite necessário.

Error: (08/12/2024 02:09:42 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-RCI3PGE)
Description: O servidor {021E4F06-9DCC-49AD-88CF-ECC2DA314C8A} não se registrou no DCOM dentro do tempo limite necessário.

Error: (08/12/2024 02:09:42 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-RCI3PGE)
Description: O servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} não se registrou no DCOM dentro do tempo limite necessário.


Windows Defender:
================
Date: 2024-08-11 22:06:48
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {B2F94B86-E00B-4FD4-B866-623FC7B663CA}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

Date: 2024-08-11 21:49:35
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {64E64BE4-04E2-4D00-A53E-E78D22A530E4}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

Date: 2024-08-11 21:36:24
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {DB31D819-D7FE-443A-B000-A529C48ECB69}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

Date: 2024-08-11 21:20:09
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {91A350D3-2D22-4E08-A9D4-E02A99EDCAEB}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

Date: 2024-08-11 21:12:47
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {001D1D09-3188-4414-B752-B795D3E8E55A}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

==================== Informações da Memória ===========================

BIOS: LENOVO EGCN41WW 06/09/2023
placa-mãe: LENOVO LNVNB161216
Processador: Intel(R) Core(TM) i7-10750H CPU @ 2.60GHz
Percentagem de memória em uso: 54%
RAM física total: 8025.68 MB
RAM física disponível: 3673.52 MB
Virtual Total: 10904.02 MB
Virtual disponível: 4337.88 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:476.28 GB) (Free:390.35 GB) (Model: INTEL SSDPEKNW512G8L) NTFS

\\?\Volume{5ca2576f-18d2-4554-b2df-f4c43dcd7a0b}\ () (Fixed) (Total:0.54 GB) (Free:0.08 GB) NTFS
\\?\Volume{6625b487-79b8-4e74-b314-15aa149f0934}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Tabela de Partições ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 476.9 GB) (Disk ID: 00000000)

Partition: GPT.

==================== Fim de Addition.txt =======================


Esse é o FRST.txt:

Resultado do análise da Farbar Recovery Scan Tool (FRST) (x64) Versão: 12-08.2024
Executado por Raphael (administrador) em DESKTOP-RCI3PGE (LENOVO 82CG) (12-08-2024 17:56:27)
Executando a partir de C:\Users\Raphael\Downloads\FRST64.exe
Perfis Carregados: Raphael
Plataforma: Microsoft Windows 10 Home Single Language Versão 22H2 19045.4651 (X64) Idioma: Português (Brasil)
Navegador padrão: Edge
Modo da Inicialização: Normal

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE -&gt (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(cmd.exe -&gt (Lenovo (Beijing) Limited -> Lenovo Group Limited) C:\Users\Raphael\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSB.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_7208949846a9b9dc\igfxCUIService.exe -&gt (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_7208949846a9b9dc\igfxEM.exe
(DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_fe9531bca29258f3\DAX3API.exe -&gt (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\DAX3_S~2.INF\DAX3API.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_1446a24b89ad2808\LenovoUtilityService.exe -&gt (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_1446a24b89ad2808\FnHotkeyCapsLKNumLK.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_1446a24b89ad2808\LenovoUtilityService.exe -&gt (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_1446a24b89ad2808\FnHotkeyUtility.exe
(gemalto -> Gemalto) C:\Program Files\SafeNet\Authentication\SAC\x64\SACMonitor.exe
(Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2407.18001.0_x64__8wekyb3d8bbwe\MicrosoftSecurityApp\MicrosoftSecurityApp.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SystemSettingsAdminFlows.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe -&gt (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe -&gt (AnyDesk Software GmbH -> AnyDesk Software GmbH) C:\Program Files (x86)\AnyDesk\AnyDesk.exe
(services.exe -&gt (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_fe9531bca29258f3\DAX3API.exe
(services.exe -&gt (gemalto -> Gemalto) C:\Program Files\SafeNet\Authentication\SAC\x64\SACSRV.exe
(services.exe -&gt (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_7208949846a9b9dc\igfxCUIService.exe
(services.exe -&gt (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_82b77f8c4618e2d0\esif_uf.exe
(services.exe -&gt (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_9cf4db1a1fd1b22d\OneApp.IGCC.WinService.exe
(services.exe -&gt (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e6980897e3126266\IntelCpHDCPSvc.exe
(services.exe -&gt (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e6980897e3126266\IntelCpHeciSvc.exe
(services.exe -&gt (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe -&gt (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_d372a4ea3b959b1c\aesm_service.exe
(services.exe -&gt (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_7aa6ca9dbb25bff8\jhi_service.exe
(services.exe -&gt (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_c98d5e0dfc88ac2f\RstMwService.exe
(services.exe -&gt (Intel(R) Trust Services -> Intel(R) Corporation) C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\SocketHeciServer.exe
(services.exe -&gt (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_1446a24b89ad2808\LenovoUtilityService.exe
(services.exe -&gt (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe -&gt (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe
(services.exe -&gt (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe
(services.exe -&gt (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe
(services.exe -&gt (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe
(services.exe -&gt (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(services.exe -&gt (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_5adc6075318430cf\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe -&gt (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(services.exe -&gt (Smart Sound Technology -> Intel) C:\Windows\System32\cAVS\IAS\IntelAudioService.exe
(svchost.exe -&gt (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileCoAuth.exe
(svchost.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\PickerHost.exe
(svchost.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.4585_none_7e06e2187c9234e2\TiWorker.exe
(svchost.exe -&gt (Skype Software Sarl -> ) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.77.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
(svchost.exe -&gt (Skype Software Sarl -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.77.0_x64__kzf8qxf38zg5c\SkypeApp.exe

==================== Registro (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [1000736 2019-10-31] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [SACMonitor] => C:\Program Files\SafeNet\Authentication\SAC\x64\SACMonitor.exe [659888 2018-07-31] (gemalto -> Gemalto)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1147774137-2360836381-337630343-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4919312 2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1147774137-2360836381-337630343-1001\...\Run: [MicrosoftEdgeAutoLaunch_617440FFEB433B15610D8CF895F6EF88] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3814968 2024-08-07] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\127.0.6533.100\Installer\chrmstp.exe [2024-08-09] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2024-08-09]
ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)

==================== Tarefas Agendadas (Whitelisted) =================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

Task: {5FF130A1-520D-477D-9373-5A924E3C536B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1563080 2024-07-31] (Adobe Inc. -> Adobe Inc.)
Task: {A7E3BCB8-2638-47D5-AA98-22982BDCFEA1} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem128.0.6598.0{9B7CE2CF-E69A-4E93-AE42-D90D14BC7A73} => C:\Program Files (x86)\Google\GoogleUpdater\128.0.6598.0\updater.exe [4888168 2024-07-15] (Google LLC -> Google LLC)
Task: {D5AC5577-796A-4051-9EB7-B7742B400821} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-1147774137-2360836381-337630343-1001 => C:\Users\Raphael\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe [88584 2024-05-17] (Lenovo (Beijing) Limited -> Lenovo Group Limited)
Task: {A5EE3E41-EDE7-4BE6-AE5D-DE09FB700ABC} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28584424 2024-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {4A43A697-CA59-4E06-9FD2-474A4D5C34C1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28584424 2024-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {858FAAD6-B9A2-42EF-AEFB-00B52FF82408} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312288 2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {7061D1A7-EF21-4C29-A3F8-5422D480E2F6} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312288 2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {236018A0-EFF3-45F7-B3D6-88CD43090994} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [182240 2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {93BF5776-01EA-454A-8B99-75A07EA646B8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {013FBB25-BB97-4BDA-89CD-51DE0BC8BC78} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CC9F27A0-C488-4B5D-B3FF-F9208FDD6554} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {67D503DA-7C3E-42E8-B273-B858DC928A06} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0463473A-CF61-4F28-89F8-796DEAC39932} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1147774137-2360836381-337630343-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [676936 2024-08-01] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (a entrada de dados tem 6 mais caracteres).
Task: {C3340D85-772A-4020-8B72-345E0DF576AF} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34376 2024-08-01] (Mozilla Corporation -> Mozilla Foundation)
Task: {E98261A5-C961-4EF0-8C5C-4A93928EC215} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2021-05-20] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {C1B1EADD-F6C1-4650-82A6-FD1AF92C2EF9} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2021-05-20] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {8753C4D4-DBD0-437E-AD69-F093D10DD76F} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3302128 2021-05-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {82E35486-C710-46B1-A6B6-D79841D8B0BF} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646896 2021-05-20] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {0CE31EA4-BCC4-48D9-A1E3-F5A0A5B9AA5C} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906480 2021-05-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {389A45EE-8D91-4BDF-8CFD-7AB04B4BB2D8} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906480 2021-05-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0EC4B10C-3E7B-4BCD-AD75-A5883AAE4496} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-05-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {DD0C02A3-D8AB-4102-BC1B-41891A0F79BA} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-05-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7916D981-6E0B-4414-AA2E-EC75EA990C38} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-05-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5948A9D8-0D6E-48BC-B41F-32F28108698D} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-05-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F72FC6EF-84D1-4DA3-B33E-0B5204E0142F} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4209168 2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {190AFC29-01F6-40CD-B4AE-2448E756130C} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1147774137-2360836381-337630343-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4209168 2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {E975AA0E-EBCE-4F46-B3C0-AC0287D942CB} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1904536 2024-07-15] (Lenovo -> )
Task: {1B794A43-D6F2-4E28-9924-6B5B07714B60} - System32\Tasks\TVT\TVSUUpdateTask_UserLogOn => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1904536 2024-07-15] (Lenovo -> )

(Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.)


==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\Parameters: [DhcpNameServer] 181.213.132.2 181.213.132.3
Tcpip\..\Interfaces\{ef6d8af2-e5cf-40ed-9ff9-e004b20a8d4d}: [DhcpNameServer] 181.213.132.2 181.213.132.3
Tcpip\..\Interfaces\{ef6d8af2-e5cf-40ed-9ff9-e004b20a8d4d}: [DhcpDomain] box
Tcpip\..\Interfaces\{ef6d8af2-e5cf-40ed-9ff9-e004b20a8d4d}\548736C657379667F6D2D4543584: [DhcpNameServer] 181.213.132.2 181.213.132.3
Tcpip\..\Interfaces\{ef6d8af2-e5cf-40ed-9ff9-e004b20a8d4d}\548736C657379667F6D2D4543584: [DhcpDomain] box
Tcpip\..\Interfaces\{ef6d8af2-e5cf-40ed-9ff9-e004b20a8d4d}\548736C657379667F6D2D4543584D294F645: [DhcpNameServer] 181.213.132.2 181.213.132.3
Tcpip\..\Interfaces\{ef6d8af2-e5cf-40ed-9ff9-e004b20a8d4d}\548736C657379667F6D2D4543584D294F645: [DhcpDomain] box
Tcpip\..\Interfaces\{f83a5eac-0687-47cd-9a03-3c0f0c5ad4f3}: [DhcpNameServer] 181.213.132.2 181.213.132.3
Tcpip\..\Interfaces\{f83a5eac-0687-47cd-9a03-3c0f0c5ad4f3}: [DhcpDomain] box

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Raphael\AppData\Local\Microsoft\Edge\User Data\Default [2024-08-12]
Edge Extension: (Certisign WebSigner Extension) - C:\Users\Raphael\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\acfifjfajpekbmhmjppnmmjgmhjkildl [2024-08-12]
Edge Extension: (Documentos Google off-line) - C:\Users\Raphael\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-08-10]
Edge Extension: (Edge relevant text changes) - C:\Users\Raphael\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-08-10]

FireFox:
========
FF DefaultProfile: 0ah68iwa.default
FF ProfilePath: C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\0ah68iwa.default [2024-08-09]
FF ProfilePath: C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\74ydnely.default-release [2024-08-12]
FF Extension: (Web PKI) - C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\74ydnely.default-release\Extensions\webpki-beta@lacunasoftware.com.xpi [2024-08-10] [UpdateUrl:hxxps://get.webpkiplugin.com/firefox-extensions]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-08-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.421.2 -> C:\Program Files (x86)\Java\jre1.8.0_421\bin\dtplugin\npDeployJava1.dll [2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.421.2 -> C:\Program Files (x86)\Java\jre1.8.0_421\bin\plugin2\npjp2.dll [2024-06-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-08-09] (Microsoft Corporation -> Microsoft Corporation)

Chrome:
=======
CHR Profile: C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default [2024-08-12]
CHR Extension: (Certisign WebSigner Extension) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\acfifjfajpekbmhmjppnmmjgmhjkildl [2024-08-12]
CHR Extension: (Web Signer) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbafmabaelnnkondpfpjmdklbmfnbmol [2024-08-09]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2024-08-10]
CHR Extension: (Documentos Google off-line) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-08-09]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Raphael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-08-09]
CHR HKU\S-1-5-21-1147774137-2360836381-337630343-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

==================== Serviços (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-07-31] (Adobe Inc. -> Adobe Inc.)
R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [5367624 2024-08-09] (AnyDesk Software GmbH -> AnyDesk Software GmbH)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13995624 2024-07-31] (Microsoft Corporation -> Microsoft Corporation)
R2 DolbyDAXAPI; C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_fe9531bca29258f3\DAX3API.exe [1928648 2020-05-19] (Dolby Laboratories, Inc. -> Dolby Laboratories)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\24.151.0728.0003\FileSyncHelper.exe [3523088 2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
R2 FMAPOService; C:\Windows\System32\FMService64.exe [390400 2020-05-22] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
R2 LenovoFnAndFunctionKeys; C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_1446a24b89ad2808\LenovoUtilityService.exe [178536 2024-05-24] (Lenovo -> Lenovo)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.24070.5-0\MpDefenderCoreService.exe [1427024 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\24.151.0728.0003\OneDriveUpdaterService.exe [3863568 2024-08-09] (Microsoft Corporation -> Microsoft Corporation)
R2 SACSrv; C:\Program Files\SafeNet\Authentication\SAC\x64\SACSRV.exe [60848 2018-07-31] (gemalto -> Gemalto)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.24070.5-0\NisSrv.exe [3199648 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.24070.5-0\MsMpEng.exe [133704 2024-08-09] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_5adc6075318430cf\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_5adc6075318430cf\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R3 AKSIFDH; C:\Windows\System32\drivers\aksifdh.sys [62632 2018-06-20] (Aladdin Knowledge Systems Inc. -> Aladdin Knowledge Systems, Ltd.)
R3 AKSUP; C:\Windows\system32\drivers\aksup.sys [44712 2018-06-20] (Aladdin Knowledge Systems Inc. -> Aladdin Knowledge Systems, Ltd.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [55608 2023-06-27] (Apple Inc. -> Apple Inc.)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [245200 2024-07-12] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klflt.K4W-21-18; C:\Windows\system32\DRIVERS\K4W-21-18\klflt.sys [723496 2024-07-12] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S3 KLIF.K4W-21-18; C:\Windows\System32\DRIVERS\K4W-21-18\klif.sys [1490368 2024-07-12] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S1 klim6; C:\Windows\system32\DRIVERS\klim6.sys [85424 2024-07-12] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 klwtp.K4W-21-18; C:\Windows\system32\DRIVERS\K4W-21-18\klwtp.sys [536800 2024-07-12] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 MpKslf44662bf; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9531AE85-024E-4A15-B8EF-CC9032A092F6}\MpKslDrv.sys [271640 2024-08-11] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [22080 2024-08-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [602504 2024-08-09] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105864 2024-08-09] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Três meses (criados) (Whitelisted) =========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2024-08-12 17:50 - 2024-08-12 17:50 - 003626388 _____ C:\Users\Raphael\Downloads\Windows.zip
2024-08-12 17:13 - 2024-08-12 17:13 - 000026702 _____ C:\Users\Raphael\Downloads\Shortcut.txt
2024-08-12 17:12 - 2024-08-12 17:13 - 000030886 _____ C:\Users\Raphael\Downloads\Addition.txt
2024-08-12 17:10 - 2024-08-12 17:56 - 000026611 _____ C:\Users\Raphael\Downloads\FRST.txt
2024-08-12 17:09 - 2024-08-12 17:56 - 000000000 ____D C:\FRST
2024-08-12 17:09 - 2024-08-12 17:09 - 002397184 _____ (Farbar) C:\Users\Raphael\Downloads\FRST64.exe
2024-08-12 16:37 - 2024-08-12 16:37 - 000038369 _____ C:\Users\Raphael\Downloads\document.pdf
2024-08-12 16:01 - 2024-08-12 16:01 - 000269116 _____ C:\Users\Raphael\Downloads\ilovepdf_merged-2.pdf
2024-08-12 16:01 - 2024-08-12 16:01 - 000269112 _____ C:\Users\Raphael\Downloads\ilovepdf_merged-1.pdf
2024-08-12 16:00 - 2024-08-12 16:00 - 000269112 _____ C:\Users\Raphael\Downloads\ilovepdf_merged.pdf
2024-08-12 15:38 - 2024-08-12 15:38 - 000170163 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-12 at 15.15.32.pdf
2024-08-12 15:19 - 2024-08-12 15:19 - 000116192 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-12 at 15.15.32.jpeg
2024-08-12 15:19 - 2024-08-12 15:19 - 000071873 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-12 at 15.15.33.jpeg
2024-08-12 14:38 - 2024-08-12 14:43 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Word
2024-08-12 14:32 - 2024-08-12 14:32 - 000099428 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-09 at 16.15.29-Manifesto (1)-1.pdf
2024-08-12 14:10 - 2024-08-12 14:10 - 000001607 _____ C:\Windows\system32\config\VSMIDK
2024-08-12 14:01 - 2024-07-26 16:18 - 000001129 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\WinThruster.lnk
2024-08-12 14:01 - 2024-07-24 22:27 - 001441792 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\MoUxCoreWorker.8143cefd-18ab-456c-87c9-820e1c910c28.1.etl
2024-08-12 14:00 - 2024-08-12 14:04 - 000000000 ____D C:\Users\Raphael\OneDrive\Área de Trabalho\saae
2024-08-12 14:00 - 2024-08-12 14:04 - 000000000 ____D C:\Users\Raphael\OneDrive\Área de Trabalho\Nova pasta
2024-08-12 14:00 - 2024-08-12 14:04 - 000000000 ____D C:\Users\Raphael\OneDrive\Área de Trabalho\LOGSMicro
2024-08-12 14:00 - 2024-08-12 14:04 - 000000000 ____D C:\Users\Raphael\OneDrive\Área de Trabalho\Decepção
2024-08-12 14:00 - 2024-08-12 14:02 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\My Kindle Content
2024-08-12 14:00 - 2024-08-12 14:00 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe!App
2024-08-12 14:00 - 2024-08-12 14:00 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Microsoft.Office.OneNote_8wekyb3d8bbwe!microsoft.onenoteim
2024-08-12 14:00 - 2024-08-12 14:00 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\IP Camera Viewer
2024-08-12 14:00 - 2024-08-12 14:00 - 000000000 ____D C:\Users\Raphael\OneDrive\Área de Trabalho\camera
2024-08-12 14:00 - 2024-07-26 16:05 - 000002324 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Reolink.lnk
2024-08-12 14:00 - 2024-07-25 19:22 - 000000951 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\LAPRAPHAEL7 - Atalho.lnk
2024-08-12 14:00 - 2024-07-25 18:58 - 000000160 _____ C:\Users\Raphael\OneDrive\Documentos\jnjjj.mp4
2024-08-12 14:00 - 2024-07-25 14:37 - 001407575 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Arquivos.zip
2024-08-12 14:00 - 2024-07-25 01:49 - 000000064 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Traidora Master.txt
2024-08-12 14:00 - 2024-07-24 18:09 - 000173817 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\download-acessos.pdf
2024-08-12 14:00 - 2024-07-24 17:25 - 000002359 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Microsoft Edge.lnk
2024-08-12 14:00 - 2024-07-23 22:25 - 000001035 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\LAPTOP-RAPHAEL raphaelfs@gmail.com - Atalho.lnk
2024-08-12 14:00 - 2024-07-23 13:06 - 000000000 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\DESCOBRIR 126e02e9-9eb9-4a48-9c15-ba19b4cbda62.txt
2024-08-12 14:00 - 2024-07-22 21:44 - 000002603 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Rave-Laptop-raphael.lnk
2024-08-12 14:00 - 2024-07-17 11:35 - 005822731 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\oui.txt
2024-08-12 14:00 - 2024-06-18 19:10 - 000117605 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Renúncia - Eliana.pdf
2024-08-12 14:00 - 2024-06-18 17:48 - 003900610 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\testre.pdf
2024-08-12 13:59 - 2024-08-12 14:04 - 000000000 ____D C:\Users\Raphael\OneDrive\Área de Trabalho\LocaleMetaData
2024-08-12 13:59 - 2024-08-12 13:59 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\PDF X
2024-08-12 13:59 - 2024-08-12 13:59 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Corel PaintShop Pro
2024-08-12 13:59 - 2024-08-12 13:59 - 000000000 ____D C:\Users\Raphael\OneDrive\Área de Trabalho\testando
2024-08-12 13:59 - 2024-06-14 08:40 - 000069632 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\X.evtx
2024-08-12 13:59 - 2024-06-14 08:40 - 000002831 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\XX.xml
2024-08-12 13:59 - 2024-06-12 09:59 - 001070622 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\wa_dyi_report.pdf
2024-08-12 13:59 - 2024-06-09 19:11 - 000006478 _____ C:\Users\Raphael\OneDrive\Documentos\Atividade do Assistente de Feedback-1.zip
2024-08-12 13:59 - 2024-05-20 09:59 - 000345967 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Site do Contribuinte.pdf
2024-08-12 13:59 - 2024-05-20 09:51 - 000063136 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Serviços PPT.pdf
2024-08-12 13:59 - 2024-05-17 11:39 - 000015468 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\CNH RAPHAEL.pdf
2024-08-12 13:58 - 2024-08-12 14:04 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Captura
2024-08-12 13:58 - 2024-08-12 14:04 - 000000000 ____D C:\Users\Raphael\OneDrive\Área de Trabalho\game
2024-08-12 13:58 - 2024-08-12 14:04 - 000000000 ____D C:\Users\Raphael\OneDrive\Área de Trabalho\andrea
2024-08-12 13:58 - 2024-08-12 14:02 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Karen
2024-08-12 13:58 - 2024-08-12 13:58 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Zoom
2024-08-12 13:58 - 2024-08-12 13:58 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Modelos Personalizados do Office
2024-08-12 13:58 - 2024-08-12 13:58 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\McAfee Vaults
2024-08-12 13:58 - 2024-06-11 15:50 - 000007666 _____ C:\Users\Raphael\OneDrive\Documentos\HP ePrint
2024-08-12 13:58 - 2023-12-12 17:24 - 000010001 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Atualização.xlsx
2024-08-12 13:58 - 2023-12-12 15:20 - 000000040 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Processo BB.txt
2024-08-12 13:58 - 2023-12-07 17:39 - 000001890 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\uTorrent Web.lnk
2024-08-12 13:58 - 2023-10-31 09:35 - 000000283 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Endereços - Inventário.txt
2024-08-12 13:58 - 2023-10-20 21:36 - 000001634 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\testamento.txt
2024-08-12 13:58 - 2023-09-26 10:19 - 000001083 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Relação processos.txt
2024-08-12 13:58 - 2023-09-21 11:08 - 000000016 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\baroni.txt
2024-08-12 13:58 - 2023-09-20 15:20 - 000000020 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\senha-padula.txt
2024-08-12 13:58 - 2023-09-04 15:59 - 000000079 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Marco Inventário.txt
2024-08-12 13:58 - 2023-08-11 18:11 - 000000014 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Acordo IPTU 2022.txt
2024-08-12 13:58 - 2023-08-08 17:11 - 000000339 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\OAB nova.txt
2024-08-12 13:58 - 2023-08-08 17:11 - 000000259 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\GOTBACKINBRAZIL.txt
2024-08-12 13:58 - 2023-08-03 19:02 - 000000181 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\cassia.txt
2024-08-12 13:58 - 2023-08-03 16:29 - 000000343 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Banco 336 - C6.txt
2024-08-12 13:58 - 2023-08-02 11:34 - 000000091 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Cartório SP.txt
2024-08-12 13:58 - 2023-07-11 09:17 - 000000055 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Ricardo Boldrini.txt
2024-08-12 13:58 - 2023-06-14 16:57 - 000001942 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Zoom.lnk
2024-08-12 13:58 - 2023-04-12 13:15 - 000000223 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Big Ambitions.url
2024-08-12 13:58 - 2023-04-05 14:30 - 000001181 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Big Ambitions - Atalho.lnk
2024-08-12 13:58 - 2022-10-05 13:47 - 000623244 _____ C:\Users\Raphael\OneDrive\Documentos\untitled.blend
2024-08-12 13:58 - 2022-09-20 11:17 - 000001045 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Processos Posto JF.txt
2024-08-12 13:58 - 2022-08-24 18:06 - 000000434 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\claudio godoy.txt
2024-08-12 13:58 - 2022-08-04 17:49 - 000000339 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\rodrigo.txt
2024-08-12 13:58 - 2022-06-08 12:06 - 000000006 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\senhaclaudemir.txt
2024-08-12 13:58 - 2022-06-07 16:34 - 000034149 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\habeas - modelo.txt
2024-08-12 13:58 - 2022-05-30 17:21 - 000000025 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Habeas Corpus.txt
2024-08-12 13:58 - 2022-05-05 15:04 - 000000650 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\alteração notificação Vibra.txt
2024-08-12 13:58 - 2022-03-17 09:30 - 000001465 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Honorários STJ.txt
2024-08-12 13:58 - 2022-02-09 18:00 - 000000150 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\ADILSON CRIME.txt
2024-08-12 13:58 - 2022-01-19 16:37 - 000000321 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Cliente oab nova.txt
2024-08-12 13:58 - 2021-12-02 10:56 - 000000938 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Partilha Ivan.txt
2024-08-12 13:58 - 2021-11-18 14:06 - 000000135 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Despesas raphael.txt
2024-08-12 13:58 - 2021-08-10 10:51 - 000000564 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\palavras.txt
2024-08-12 13:58 - 2021-07-13 21:17 - 000000054 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\acompanhar.txt
2024-08-12 13:58 - 2021-07-08 16:00 - 000019659 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\ivan aluguel.txt
2024-08-12 13:58 - 2021-06-17 09:24 - 000002727 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\office.cmd
2024-08-12 13:58 - 2021-03-11 10:51 - 000000335 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Senhas processos.txt
2024-08-12 13:58 - 2021-01-27 13:40 - 000082694 _____ C:\Users\Raphael\OneDrive\Documentos\Relação Aluno e professor.pptx
2024-08-12 13:58 - 2020-09-28 15:17 - 000002710 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Bens Ivan.txt
2024-08-12 13:58 - 2020-09-15 10:23 - 000000499 _____ C:\Users\Raphael\OneDrive\Documentos\Reclamação Claro.txt
2024-08-12 13:58 - 2020-09-10 15:17 - 000000141 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\PRESCRIÇÃO DE DÍVIDA - PETROBRAS.txt
2024-08-12 13:57 - 2024-08-12 14:04 - 000000000 ____D C:\Users\Raphael\OneDrive\Área de Trabalho\Emulator2
2024-08-12 13:57 - 2024-08-12 14:02 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Reforma
2024-08-12 13:57 - 2024-08-12 14:02 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\OpenTTD
2024-08-12 13:57 - 2024-08-12 14:02 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Livros
2024-08-12 13:57 - 2024-08-12 14:02 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Gravidez
2024-08-12 13:57 - 2024-08-12 14:01 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Cavern
2024-08-12 13:57 - 2024-08-12 13:58 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\XuanZhi
2024-08-12 13:57 - 2024-08-12 13:57 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Sports Interactive
2024-08-12 13:57 - 2024-08-12 13:57 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Polymorph Games
2024-08-12 13:57 - 2024-08-12 13:57 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\My Games
2024-08-12 13:57 - 2024-02-06 22:28 - 000458449 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\821-827.pdf
2024-08-12 13:57 - 2024-02-06 22:28 - 000076006 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\236-239.pdf
2024-08-12 13:57 - 2024-02-06 14:11 - 000039777 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\DOL - Indicação.pdf
2024-08-12 13:57 - 2024-01-11 15:11 - 000120757 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Comprovante Endereço - ALEXANDRE BARONI (1).pdf
2024-08-12 13:57 - 2023-11-10 15:48 - 000118216 _____ C:\Users\Raphael\OneDrive\Documentos\Documento 2.pdf
2024-08-12 13:57 - 2023-02-28 14:53 - 000072180 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Portal de Serviços e-SAJ.pdf
2024-08-12 13:57 - 2023-02-24 15:42 - 001157049 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Edital.pdf
2024-08-12 13:57 - 2023-02-22 13:36 - 003379656 _____ (Mojang) C:\Users\Raphael\OneDrive\Área de Trabalho\Minecraft.exe
2024-08-12 13:57 - 2022-11-17 14:01 - 000031419 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\doc_191501201.pdf
2024-08-12 13:57 - 2021-01-27 13:43 - 000090015 _____ C:\Users\Raphael\OneDrive\Documentos\Relação Aluno e professor.pdf
2024-08-12 13:57 - 2020-06-10 10:47 - 000080101 _____ C:\Users\Raphael\OneDrive\Documentos\Currículo Raphael Sanchez-.pdf
2024-08-12 13:57 - 2020-06-10 10:24 - 000080023 _____ C:\Users\Raphael\OneDrive\Documentos\Currículo Raphael Sanchez.pdf
2024-08-12 13:57 - 2020-06-08 14:22 - 000434252 _____ C:\Users\Raphael\OneDrive\Documentos\Comprovante - res..pdf
2024-08-12 13:57 - 2020-01-10 10:52 - 000074872 _____ C:\Users\Raphael\OneDrive\Documentos\SanchezEValeriano.pdf
2024-08-12 13:57 - 2020-01-06 08:53 - 001587317 _____ C:\Users\Raphael\OneDrive\Documentos\Boletos OAB.pdf
2024-08-12 13:57 - 2019-05-02 16:07 - 000340587 _____ C:\Users\Raphael\OneDrive\Documentos\apostas.pdf
2024-08-12 13:57 - 2019-02-28 14:10 - 003152675 _____ C:\Users\Raphael\OneDrive\Documentos\Apostila de Direito e Legislação.pdf
2024-08-12 13:56 - 2024-08-12 13:56 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Contatos
2024-08-12 13:56 - 2024-08-12 13:56 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Arquivos do Outlook
2024-08-12 13:56 - 2024-03-18 14:30 - 000004342 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\seila.txt
2024-08-12 13:56 - 2024-03-13 15:47 - 000000371 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Among Us.url
2024-08-12 13:55 - 2024-08-12 14:02 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\iLovePDF_Output
2024-08-12 13:55 - 2024-08-12 14:02 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Gravações de som
2024-08-12 13:55 - 2024-08-12 14:01 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Advocacia
2024-08-12 13:55 - 2024-08-12 13:57 - 000000000 ____D C:\Users\Raphael\OneDrive\Documentos\Rockstar Games
2024-08-12 13:55 - 2024-08-12 13:55 - 000000000 ___HD C:\OneDriveTemp
2024-08-12 13:55 - 2024-06-16 22:55 - 000012018 _____ C:\Users\Raphael\OneDrive\Documentos\Pasta1.xlsx
2024-08-12 13:55 - 2024-04-30 14:19 - 000000223 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Stumble Guys.url
2024-08-12 13:55 - 2024-04-22 16:09 - 000314452 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Ação Ordinária - Mario Daniel La Gatto.pdf
2024-08-12 13:55 - 2024-04-17 02:22 - 000079073 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Débitos Atualizados - Tremendão 04-2024.pdf
2024-08-12 13:55 - 2024-04-13 18:53 - 000002334 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Rave.lnk
2024-08-12 13:55 - 2024-04-04 14:16 - 000002751 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\Demonstrativo de Pagamento (2).pdf
2024-08-12 13:55 - 2024-03-28 15:17 - 000000873 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\My Lockbox Control Panel.lnk
2024-08-12 13:55 - 2024-03-28 15:17 - 000000871 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\My Lockbox.lnk
2024-08-12 13:38 - 2024-08-12 13:38 - 000099428 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-09 at 16.15.29-Manifesto (1).pdf
2024-08-12 13:36 - 2024-08-12 13:36 - 000018510 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-09 at 16.15.29-Original-Manifesto (1).pdf
2024-08-12 13:35 - 2024-08-12 13:35 - 000018531 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-09 at 16.15.29-Original-Manifesto.pdf
2024-08-12 13:32 - 2024-08-12 13:32 - 000104376 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-09 at 16.15.29-Original (1).jpeg
2024-08-12 13:30 - 2024-08-12 13:30 - 000594387 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-09 at 16.15.29.zip
2024-08-12 13:30 - 2024-08-12 13:30 - 000104376 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-09 at 16.15.29-Original.jpeg
2024-08-12 13:29 - 2024-08-12 13:29 - 000018474 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-09 at 16.15.29-Manifesto.pdf
2024-08-12 13:28 - 2024-08-12 13:28 - 000051405 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-09 at 16.15.29.pdf
2024-08-12 13:26 - 2024-08-12 13:26 - 003665920 _____ C:\Users\Raphael\Downloads\WebSignerSetup_2.9.0_pt-BR.msi
2024-08-12 13:26 - 2024-08-12 13:26 - 000000000 ____D C:\Users\Raphael\AppData\Local\Certisign
2024-08-12 12:41 - 2024-08-12 12:41 - 001068439 _____ C:\Users\Raphael\Downloads\AC004045156_Anexos_Todos.zip
2024-08-12 12:41 - 2024-08-12 12:41 - 000676899 _____ C:\Users\Raphael\Downloads\4946425.pdf
2024-08-12 12:40 - 2024-08-12 12:40 - 066465344 _____ (Certisign Certificadora Digital ) C:\Users\Raphael\Downloads\Setup_desktopID.exe
2024-08-12 12:35 - 2024-08-12 12:35 - 000625078 _____ C:\Users\Raphael\Downloads\0014836-29.2020.8.26.0114.pdf
2024-08-12 12:29 - 2024-08-12 12:29 - 000050915 _____ C:\Users\Raphael\Downloads\054243883300262.pdf
2024-08-12 12:28 - 2024-08-12 12:28 - 000050911 _____ C:\Users\Raphael\Downloads\054244044440716-1.pdf
2024-08-12 12:28 - 2024-08-12 12:28 - 000050911 _____ C:\Users\Raphael\Downloads\054244044440716.pdf
2024-08-12 12:27 - 2024-08-12 12:27 - 000051052 _____ C:\Users\Raphael\Downloads\054244045238689.pdf
2024-08-12 12:27 - 2024-08-12 12:27 - 000051052 _____ C:\Users\Raphael\Downloads\054244045173589.pdf
2024-08-12 12:27 - 2024-08-12 12:27 - 000050910 _____ C:\Users\Raphael\Downloads\054244045243523.pdf
2024-08-12 12:26 - 2024-08-12 12:26 - 000132222 _____ C:\Users\Raphael\Downloads\WhatsApp Image 2024-08-09 at 16.15.29.jpeg
2024-08-12 11:51 - 2024-08-12 11:51 - 000051690 _____ C:\Users\Raphael\Downloads\054243892250136.pdf
2024-08-12 11:51 - 2024-08-12 11:51 - 000051100 _____ C:\Users\Raphael\Downloads\054243992303579.pdf
2024-08-12 11:51 - 2024-08-12 11:51 - 000050832 _____ C:\Users\Raphael\Downloads\054244043805208.pdf
2024-08-12 11:50 - 2024-08-12 11:50 - 000050046 _____ C:\Users\Raphael\Downloads\054244044438223.pdf
2024-08-11 21:57 - 2024-08-11 21:57 - 000000000 ____D C:\Windows\LastGood.Tmp
2024-08-11 21:28 - 2024-08-11 21:28 - 000000000 ____D C:\Users\Raphael\AppData\Local\NVIDIA
2024-08-11 21:27 - 2024-08-11 21:27 - 000000000 ____D C:\Users\Raphael\AppData\Local\CEF
2024-08-10 19:08 - 2024-08-10 19:08 - 000014636 _____ C:\Users\Raphael\Downloads\imprimir - 2024-08-06T085927.493.pdf
2024-08-10 19:08 - 2024-08-10 19:08 - 000001610 _____ C:\Users\Raphael\Downloads\ComprovanteBB - 2024-08-06-133352.pdf
2024-08-10 18:47 - 2024-08-10 18:47 - 015434240 _____ C:\Users\Raphael\Downloads\certisign10.6-x64-10.6.exe
2024-08-10 18:47 - 2024-08-10 18:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SafeNet
2024-08-10 18:47 - 2024-08-10 18:47 - 000000000 ____D C:\Program Files\SafeNet
2024-08-10 18:47 - 2024-08-10 18:47 - 000000000 ____D C:\Program Files (x86)\Gemalto
2024-08-10 18:47 - 2018-06-20 18:28 - 000062632 _____ (Aladdin Knowledge Systems, Ltd.) C:\Windows\system32\Drivers\aksifdh.sys
2024-08-10 18:46 - 2024-08-10 18:46 - 000000000 ____D C:\Users\Raphael\AppData\Local\Lacuna Software
2024-08-10 18:45 - 2024-08-10 18:45 - 004411392 _____ C:\Users\Raphael\Downloads\WebPkiSetup_2.12.3_pt.msi
2024-08-10 13:56 - 2024-08-10 13:56 - 000001176 _____ C:\Users\Raphael\OneDrive\Área de Trabalho\DESKTOP-RCI3PGE - Atalho.lnk
2024-08-10 13:52 - 2024-08-11 18:52 - 000000000 ____D C:\Users\Raphael\AppData\Local\ElevatedDiagnostics
2024-08-10 02:41 - 2024-08-10 02:41 - 000000000 ____D C:\Users\Raphael\AppData\Local\OneDrive
2024-08-09 23:49 - 2024-08-09 23:49 - 000000000 ____D C:\Windows\system32\compatrel
2024-08-09 23:45 - 2024-08-11 18:19 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2024-08-09 23:45 - 2024-08-09 23:45 - 000000000 ____D C:\Windows\system32\%userprofile%
2024-08-09 23:20 - 2024-08-09 23:20 - 000472245 _____ C:\Users\Raphael\Downloads\fatura.pdf
2024-08-09 22:18 - 2024-08-09 22:18 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2024-08-09 20:35 - 2024-08-09 20:35 - 000119571 _____ C:\Users\Raphael\Downloads\Todos os contatos(1).vcf
2024-08-09 20:31 - 2024-08-09 20:31 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\QuickStyles
2024-08-09 20:30 - 2024-08-12 14:38 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\UProof
2024-08-09 20:30 - 2024-08-12 14:38 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Office
2024-08-09 20:30 - 2024-08-09 20:30 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Proof
2024-08-09 20:30 - 2024-08-09 20:30 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Outlook
2024-08-09 20:30 - 2024-08-09 20:30 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\AddIns
2024-08-09 20:29 - 2024-08-09 23:45 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2024-08-09 20:29 - 2024-08-09 23:45 - 000002138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-08-09 20:29 - 2024-08-09 23:45 - 000000000 ___RD C:\Users\Default\OneDrive
2024-08-09 20:29 - 2024-08-09 20:29 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2024-08-09 20:28 - 2024-08-09 20:28 - 000002483 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2024-08-09 20:28 - 2024-08-09 20:28 - 000002475 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sticky Notes (Preview).lnk
2024-08-09 20:28 - 2024-08-09 20:28 - 000002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2024-08-09 20:28 - 2024-08-09 20:28 - 000002432 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2024-08-09 20:28 - 2024-08-09 20:28 - 000002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2024-08-09 20:28 - 2024-08-09 20:28 - 000002419 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk
2024-08-09 20:28 - 2024-08-09 20:28 - 000002415 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook (classic).lnk
2024-08-09 20:28 - 2024-08-09 20:28 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2024-08-09 20:28 - 2024-08-09 20:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ferramentas do Microsoft Office
2024-08-09 20:27 - 2024-08-09 20:28 - 000000000 ____D C:\Program Files\Microsoft Office
2024-08-09 20:27 - 2024-08-09 20:27 - 000000000 ____D C:\Program Files\Microsoft Office 15
2024-08-09 20:26 - 2024-08-09 20:26 - 000119571 _____ C:\Users\Raphael\Downloads\Todos os contatos.vcf
2024-08-09 19:59 - 2024-08-09 19:59 - 000154638 _____ C:\Users\Raphael\Downloads\takeout-20240808T060607Z-001.zip
2024-08-09 19:59 - 2024-08-09 19:59 - 000154638 _____ C:\Users\Raphael\Downloads\takeout-20240808T060607Z-001(1).zip
2024-08-09 19:30 - 2024-08-09 20:38 - 000000000 ____D C:\Users\Raphael\AppData\LocalLow\Adobe
2024-08-09 19:30 - 2024-08-09 19:30 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\com.adobe.dunamis
2024-08-09 19:30 - 2024-08-09 19:30 - 000000000 ____D C:\Users\Raphael\AppData\Local\SolidDocuments
2024-08-09 19:30 - 2024-08-09 19:30 - 000000000 ____D C:\Users\Raphael\.ms-ad
2024-08-09 19:30 - 2024-08-09 19:30 - 000000000 ____D C:\ProgramData\Adobe
2024-08-09 19:23 - 2024-08-09 19:23 - 000021724 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-08-09 19:22 - 2024-08-09 19:22 - 000021724 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2024-08-09 19:19 - 2024-08-09 19:19 - 000000000 ___HD C:\$WinREAgent
2024-08-09 19:18 - 2024-08-11 21:27 - 000000000 ____D C:\Users\Raphael\AppData\Local\NVIDIA Corporation
2024-08-09 19:18 - 2024-08-09 23:45 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1147774137-2360836381-337630343-1001
2024-08-09 19:18 - 2024-08-09 19:18 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2024-08-09 19:17 - 2024-08-09 19:17 - 000000000 ____D C:\Program Files\RUXIM
2024-08-09 19:15 - 2024-08-09 19:16 - 000000000 ____D C:\Windows\Minidump
2024-08-09 19:15 - 2024-08-09 19:15 - 1178368667 _____ C:\Windows\MEMORY.DMP
2024-08-09 19:15 - 2024-08-09 19:15 - 002190900 _____ C:\Windows\Minidump\080924-9140-01.dmp
2024-08-09 19:15 - 2024-08-09 19:15 - 000000000 ____D C:\Windows\system32\Tasks\Intel
2024-08-09 17:53 - 2024-08-09 19:17 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2024-08-09 17:53 - 2024-08-09 17:53 - 000000000 ____D C:\Windows\system32\Drivers\K4W-21-18
2024-08-09 17:53 - 2024-08-09 17:53 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2024-08-09 17:45 - 2020-11-30 03:28 - 000337288 _____ (Intel Corporation) C:\Windows\system32\JHI64.dll
2024-08-09 17:45 - 2020-11-30 03:28 - 000321416 _____ (Intel Corporation) C:\Windows\system32\TEEManagement64.dll
2024-08-09 17:45 - 2020-11-30 03:28 - 000272264 _____ (Intel Corporation) C:\Windows\SysWOW64\JHI.dll
2024-08-09 17:45 - 2020-11-30 03:28 - 000259464 _____ (Intel Corporation) C:\Windows\SysWOW64\TEEManagement.dll
2024-08-09 17:41 - 2024-08-09 17:41 - 000000000 ____D C:\Windows\system32\lxss
2024-08-09 17:40 - 2024-08-09 17:54 - 000000000 ____D C:\Windows\system32\MRT
2024-08-09 17:40 - 2021-07-28 16:32 - 001453696 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2024-08-09 17:40 - 2021-07-28 16:32 - 001193088 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2024-08-09 17:39 - 2021-07-28 16:29 - 000715920 _____ C:\Windows\system32\nvofapi64.dll
2024-08-09 17:39 - 2021-07-28 16:29 - 000626296 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2024-08-09 17:39 - 2021-07-28 16:29 - 000576120 _____ C:\Windows\SysWOW64\nvofapi.dll
2024-08-09 17:39 - 2021-07-28 16:28 - 001515136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2024-08-09 17:39 - 2021-07-28 16:28 - 001166976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2024-08-09 17:39 - 2021-07-28 16:28 - 000690304 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2024-08-09 17:39 - 2021-07-28 16:28 - 000675440 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2024-08-09 17:39 - 2021-07-28 16:28 - 000564352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2024-08-09 17:39 - 2021-07-28 16:27 - 008317560 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2024-08-09 17:39 - 2021-07-28 16:27 - 007434880 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2024-08-09 17:39 - 2021-07-28 16:27 - 004796016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2024-08-09 17:39 - 2021-07-28 16:27 - 002823808 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2024-08-09 17:39 - 2021-07-28 16:27 - 002106504 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2024-08-09 17:39 - 2021-07-28 16:27 - 001591432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2024-08-09 17:39 - 2021-07-28 16:27 - 000812680 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2024-08-09 17:39 - 2021-07-28 16:27 - 000656504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2024-08-09 17:39 - 2021-07-28 16:27 - 000280688 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2024-08-09 17:39 - 2021-07-28 16:26 - 005680256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2024-08-09 17:39 - 2021-07-28 16:26 - 000849008 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2024-08-09 17:39 - 2021-07-28 16:25 - 006160176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2024-08-09 17:39 - 2021-07-19 09:22 - 000087652 _____ C:\Windows\system32\nvinfo.pb
2024-08-09 17:38 - 2024-08-09 17:38 - 000000000 ____D C:\Users\Raphael\AppData\Local\Lenovo
2024-08-09 17:38 - 2024-08-09 17:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\lenovo
2024-08-09 17:38 - 2024-08-09 17:38 - 000000000 ____D C:\Program Files (x86)\Lenovo
2024-08-09 17:37 - 2024-08-12 12:35 - 000000000 ____D C:\Users\Raphael\AppData\Local\CrashDumps
2024-08-09 17:37 - 2024-08-09 17:37 - 000000296 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2024-08-09 17:23 - 2020-05-19 21:15 - 002914224 _____ (Intel Corporation) C:\Windows\system32\iaStorAfsService.exe
2024-08-09 17:23 - 2020-05-19 21:15 - 000210864 _____ (Intel Corporation) C:\Windows\system32\iaStorAfsNative.exe
2024-08-09 17:23 - 2020-05-08 21:54 - 001346528 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorAC.sys
2024-08-09 17:23 - 2020-05-08 21:54 - 000115176 _____ (Intel Corporation) C:\Windows\system32\Optane.dll
2024-08-09 17:23 - 2020-05-08 21:54 - 000074208 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorAfs.sys
2024-08-09 17:23 - 2020-05-08 21:54 - 000027624 _____ (Intel Corporation) C:\Windows\system32\RstMwEventLogMsg.dll
2024-08-09 17:23 - 2020-05-08 21:54 - 000024552 _____ (Intel Corporation) C:\Windows\system32\OptaneEventLogMsg.dll
2024-08-09 17:22 - 2024-08-12 14:13 - 000000000 ____D C:\ProgramData\NVIDIA
2024-08-09 17:22 - 2024-08-09 17:22 - 000004308 _____ C:\Windows\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-08-09 17:22 - 2024-08-09 17:22 - 000004106 _____ C:\Windows\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-08-09 17:22 - 2024-08-09 17:22 - 000003976 _____ C:\Windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-08-09 17:22 - 2024-08-09 17:22 - 000003940 _____ C:\Windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-08-09 17:22 - 2024-08-09 17:22 - 000003894 _____ C:\Windows\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-08-09 17:22 - 2024-08-09 17:22 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-08-09 17:22 - 2024-08-09 17:22 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-08-09 17:22 - 2024-08-09 17:22 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-08-09 17:22 - 2024-08-09 17:22 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-08-09 17:22 - 2024-08-09 17:22 - 000003654 _____ C:\Windows\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-08-09 17:22 - 2024-08-09 17:22 - 000000000 ____D C:\ProgramData\Package Cache
2024-08-09 17:22 - 2024-08-09 17:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2024-08-09 17:22 - 2024-08-09 17:22 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2024-08-09 17:22 - 2021-05-20 16:54 - 002797808 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2024-08-09 17:22 - 2021-05-20 16:54 - 002154224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2024-08-09 17:22 - 2021-05-20 16:54 - 001295088 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2024-08-09 17:22 - 2021-05-20 16:54 - 000169272 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2024-08-09 17:22 - 2021-05-20 16:54 - 000145208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2024-08-09 17:22 - 2021-05-20 16:54 - 000069840 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2024-08-09 17:22 - 2021-05-20 16:54 - 000067456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2024-08-09 17:22 - 2021-05-20 16:54 - 000050592 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\NvModuleTracker.sys
2024-08-09 17:22 - 2021-05-20 16:51 - 000070896 _____ C:\Windows\system32\FvSDK_x64.dll
2024-08-09 17:22 - 2021-05-20 16:51 - 000059632 _____ C:\Windows\SysWOW64\FvSDK_x86.dll
2024-08-09 17:22 - 2020-06-01 20:13 - 001146456 _____ (Realtek ) C:\Windows\system32\Drivers\rt640x64.sys
2024-08-09 17:21 - 2022-03-25 13:54 - 005162552 _____ (Intel Corporation) C:\Windows\system32\Drivers\Netwtw10.sys
2024-08-09 17:21 - 2022-03-25 13:54 - 001529416 _____ (Intel Corporation) C:\Windows\system32\IntelIHVRouter08.dll
2024-08-09 17:20 - 2024-08-10 00:30 - 000000000 ____D C:\ProgramData\Lenovo
2024-08-09 17:20 - 2024-08-09 19:15 - 000000000 ____D C:\Windows\TempInst
2024-08-09 17:20 - 2024-08-09 17:38 - 000000000 ____D C:\Windows\system32\Tasks\TVT
2024-08-09 17:20 - 2024-08-09 17:20 - 000000000 ____D C:\Users\Raphael\AppData\Local\LenovoServiceBridge
2024-08-09 17:19 - 2024-08-09 20:40 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2024-08-09 17:19 - 2024-08-09 20:40 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2024-08-09 17:19 - 2024-08-09 17:21 - 000000000 ____D C:\ProgramData\ProductData
2024-08-09 17:19 - 2024-08-09 17:21 - 000000000 ____D C:\Program Files (x86)\IObit
2024-08-09 17:19 - 2024-08-09 17:19 - 000000000 ____D C:\Program Files\Adobe
2024-08-09 17:18 - 2024-08-09 17:19 - 000000000 ____D C:\Program Files\Common Files\Adobe
2024-08-09 17:18 - 2024-08-09 17:18 - 029733912 _____ (IObit ) C:\Users\Raphael\Downloads\driver_booster_setup.exe
2024-08-09 17:16 - 2024-08-09 19:31 - 000000000 ____D C:\Users\Raphael\AppData\Local\Adobe
2024-08-09 17:15 - 2024-08-09 17:15 - 004683640 _____ (Kaspersky) C:\Users\Raphael\Downloads\kaspersky4win202121.18.5.438pt_46479.exe
2024-08-09 17:15 - 2024-08-09 17:15 - 002365032 _____ (Oracle Corporation) C:\Users\Raphael\Downloads\JavaSetup8u421.exe
2024-08-09 17:15 - 2024-08-09 17:15 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Sun
2024-08-09 17:15 - 2024-08-09 17:15 - 000000000 ____D C:\Users\Raphael\AppData\LocalLow\Sun
2024-08-09 17:15 - 2024-08-09 17:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2024-08-09 17:15 - 2024-08-09 17:15 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2024-08-09 17:15 - 2024-08-09 17:15 - 000000000 ____D C:\Program Files (x86)\Java
2024-08-09 17:15 - 2024-06-05 13:24 - 000178816 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2024-08-09 17:14 - 2024-08-09 17:14 - 003812528 _____ (Lenovo ) C:\Users\Raphael\Downloads\LSBSetup.exe
2024-08-09 17:14 - 2024-08-09 17:14 - 000000000 ____D C:\Windows\system32\Tasks\Lenovo
2024-08-09 17:14 - 2024-08-09 17:14 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2024-08-09 17:14 - 2024-08-09 17:14 - 000000000 ____D C:\Users\Raphael\AppData\Local\Google
2024-08-09 17:12 - 2024-08-12 16:39 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-08-09 17:12 - 2024-08-09 17:47 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2024-08-09 17:12 - 2024-08-09 17:12 - 000425304 _____ (Secure By Design Inc.) C:\Users\Raphael\Downloads\Ninite 7Zip Chrome Firefox Revo Installer.exe
2024-08-09 17:12 - 2024-08-09 17:12 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-08-09 17:12 - 2024-08-09 17:12 - 000002050 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navegação privativa do Firefox.lnk
2024-08-09 17:12 - 2024-08-09 17:12 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\Windows\system32\Tasks\GoogleSystem
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Mozilla
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\Users\Raphael\AppData\Local\Mozilla
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\Program Files\VS Revo Group
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\Program Files\Mozilla Firefox
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\Program Files\Google
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\Program Files\7-Zip
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-08-09 17:12 - 2024-08-09 17:12 - 000000000 ____D C:\Program Files (x86)\Google
2024-08-09 17:10 - 2024-08-09 17:11 - 000000000 ____D C:\ProgramData\AnyDesk
2024-08-09 17:10 - 2024-08-09 17:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyDesk
2024-08-09 17:10 - 2024-08-09 17:10 - 000000000 ____D C:\Program Files (x86)\AnyDesk
2024-08-09 16:50 - 2024-08-09 16:50 - 000000533 _____ C:\Windows\system32\regtest.txt
2024-08-09 16:50 - 2024-08-09 16:50 - 000000000 ____D C:\ProgramData\Dolby
2024-08-09 16:49 - 2019-10-31 01:29 - 005601536 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPOU64.dll
2024-08-09 16:49 - 2019-10-31 01:29 - 001126336 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtCOM64.dll
2024-08-09 16:49 - 2019-10-31 01:29 - 001000736 _____ (Realtek Semiconductor) C:\Windows\system32\RtkAudUService64.exe
2024-08-09 16:49 - 2019-10-31 01:29 - 000833616 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64U.dll
2024-08-09 16:49 - 2019-10-31 01:29 - 000481888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2024-08-09 16:49 - 2019-10-31 01:29 - 000215032 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2024-08-09 16:48 - 2024-08-10 02:44 - 000000000 ____D C:\Users\Raphael\AppData\Local\D3DSCache
2024-08-09 16:48 - 2024-08-09 16:49 - 000000000 ____D C:\Windows\system32\dolbyaposvc
2024-08-09 16:48 - 2024-08-09 16:48 - 000000000 ____D C:\Windows\system32\Intel
2024-08-09 16:48 - 2024-08-09 16:48 - 000000000 ____D C:\Windows\system32\cAVS
2024-08-09 16:48 - 2020-06-04 01:44 - 007359080 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2024-08-09 16:47 - 2024-08-11 21:27 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2024-08-09 16:47 - 2024-08-09 17:22 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2024-08-09 16:47 - 2024-08-09 16:47 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2024-08-09 16:47 - 2021-08-31 17:54 - 000144016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2024-08-09 16:47 - 2021-08-31 17:54 - 000047248 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhdap64.dll
2024-08-09 16:47 - 2021-07-28 16:25 - 007212744 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2024-08-09 16:45 - 2024-08-12 14:11 - 000000000 __SHD C:\Users\Raphael\IntelGraphicsProfiles
2024-08-09 16:45 - 2024-08-12 14:10 - 000000000 ____D C:\Intel
2024-08-09 16:45 - 2024-08-09 19:15 - 000000000 ____D C:\ProgramData\Intel
2024-08-09 16:45 - 2024-08-09 16:45 - 000000000 ____D C:\Users\Raphael\AppData\LocalLow\Intel
2024-08-09 16:45 - 2024-08-09 16:45 - 000000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2024-08-09 16:45 - 2020-03-27 02:03 - 005422024 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RsDMFT64.dll
2024-08-09 16:44 - 2021-08-03 02:55 - 001859608 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2024-08-09 16:44 - 2021-08-03 02:55 - 001859608 _____ C:\Windows\system32\vulkaninfo.exe
2024-08-09 16:44 - 2021-08-03 02:55 - 001440280 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2024-08-09 16:44 - 2021-08-03 02:55 - 001440280 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2024-08-09 16:44 - 2021-08-03 02:55 - 001102312 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2024-08-09 16:44 - 2021-08-03 02:55 - 001102312 _____ C:\Windows\system32\vulkan-1.dll
2024-08-09 16:44 - 2021-08-03 02:55 - 000956416 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2024-08-09 16:44 - 2021-08-03 02:55 - 000956416 _____ C:\Windows\SysWOW64\vulkan-1.dll
2024-08-09 16:44 - 2021-08-03 02:55 - 000309664 _____ (Intel Corporation) C:\Windows\system32\libmfxhw64.dll
2024-08-09 16:44 - 2021-08-03 02:55 - 000257064 _____ (Intel Corporation) C:\Windows\SysWOW64\libmfxhw32.dll
2024-08-09 16:44 - 2021-08-03 02:55 - 000173064 _____ (Intel Corporation) C:\Windows\system32\intel_gfx_api-x64.dll
2024-08-09 16:44 - 2021-08-03 02:55 - 000148368 _____ (Intel Corporation) C:\Windows\SysWOW64\intel_gfx_api-x86.dll
2024-08-09 16:43 - 2024-08-11 19:42 - 000000000 ____D C:\Users\Raphael\AppData\Local\PlaceholderTileLogoFolder
2024-08-09 16:43 - 2024-08-09 17:09 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\AnyDesk
2024-08-09 16:43 - 2024-08-09 16:43 - 005367624 _____ (AnyDesk Software GmbH) C:\Users\Raphael\Downloads\AnyDesk.exe
2024-08-09 16:43 - 2024-08-09 16:43 - 000394240 _____ (Google Inc.) C:\Users\Raphael\Downloads\gcapi.dll
2024-08-09 16:24 - 2024-08-12 17:52 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\MMC
2024-08-09 16:20 - 2024-08-09 20:00 - 000000000 ____D C:\Users\Raphael\AppData\Local\Comms
2024-08-09 16:12 - 2024-08-09 16:24 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Spelling
2024-08-09 15:57 - 2024-08-12 14:11 - 000000000 ___RD C:\Users\Raphael\OneDrive
2024-08-09 15:57 - 2024-08-09 15:57 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2024-08-09 15:55 - 2024-08-12 14:16 - 001651882 _____ C:\Windows\system32\PerfStringBackup.INI
2024-08-09 15:55 - 2024-08-12 14:03 - 000000000 ____D C:\Users\Raphael\AppData\Local\Packages
2024-08-09 15:55 - 2024-08-12 14:03 - 000000000 ____D C:\ProgramData\Packages
2024-08-09 15:55 - 2024-08-09 23:51 - 000000000 ____D C:\Users\Raphael\AppData\Local\ConnectedDevicesPlatform
2024-08-09 15:55 - 2024-08-09 20:30 - 000000000 __RHD C:\Users\Public\AccountPictures
2024-08-09 15:55 - 2024-08-09 19:30 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Adobe
2024-08-09 15:55 - 2024-08-09 16:45 - 000000000 ____D C:\Users\Raphael\AppData\Local\Publishers
2024-08-09 15:55 - 2024-08-09 15:55 - 000000000 ___SD C:\Users\Raphael\AppData\Roaming\Microsoft\SystemCertificates
2024-08-09 15:55 - 2024-08-09 15:55 - 000000000 ___SD C:\Users\Raphael\AppData\Roaming\Microsoft\Protect
2024-08-09 15:55 - 2024-08-09 15:55 - 000000000 ___SD C:\Users\Raphael\AppData\Roaming\Microsoft\Crypto
2024-08-09 15:55 - 2024-08-09 15:55 - 000000000 ___SD C:\Users\Raphael\AppData\Roaming\Microsoft\Credentials
2024-08-09 15:55 - 2024-08-09 15:55 - 000000000 ___RD C:\Users\Raphael\3D Objects
2024-08-09 15:55 - 2024-08-09 15:55 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Vault
2024-08-09 15:55 - 2024-08-09 15:55 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Network
2024-08-09 15:55 - 2024-08-09 15:55 - 000000000 ____D C:\Users\Raphael\AppData\Local\VirtualStore
2024-08-09 15:54 - 2024-08-12 14:11 - 000000000 ____D C:\Users\Raphael
2024-08-09 15:54 - 2024-08-09 15:55 - 000000000 ____D C:\Users\Raphael\AppData\Roaming\Microsoft\Windows
2024-08-09 15:54 - 2024-08-09 15:54 - 000000020 ___SH C:\Users\Raphael\ntuser.ini
2024-08-09 15:54 - 2024-08-09 15:54 - 000000000 _SHDL C:\Users\Raphael\Modelos
2024-08-09 15:54 - 2024-08-09 15:54 - 000000000 _SHDL C:\Users\Raphael\Meus Documentos
2024-08-09 15:54 - 2024-08-09 15:54 - 000000000 _SHDL C:\Users\Raphael\Menu Iniciar
2024-08-09 15:54 - 2024-08-09 15:54 - 000000000 _SHDL C:\Users\Raphael\Dados de Aplicativos
2024-08-09 15:54 - 2024-08-09 15:54 - 000000000 _SHDL C:\Users\Raphael\Configurações Locais
2024-08-09 15:54 - 2024-08-09 15:54 - 000000000 _SHDL C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2024-08-09 15:54 - 2024-08-09 15:54 - 000000000 _SHDL C:\Users\Raphael\AppData\Local\Histórico
2024-08-09 15:54 - 2024-08-09 15:54 - 000000000 _SHDL C:\Users\Raphael\AppData\Local\Dados de Aplicativos
2024-08-09 15:54 - 2024-08-09 15:54 - 000000000 _SHDL C:\Users\Raphael\Ambiente de Rede
2024-08-09 15:54 - 2024-08-09 15:54 - 000000000 _SHDL C:\Users\Raphael\Ambiente de Impressão
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Usuário Padrão
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Todos os Usuários
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Default\Modelos
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Default\Meus Documentos
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Default\Menu Iniciar
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Default\Dados de Aplicativos
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Default\Configurações Locais
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Default\AppData\Local\Histórico
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Default\AppData\Local\Dados de Aplicativos
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Default\Ambiente de Rede
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Users\Default\Ambiente de Impressão
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\ProgramData\Modelos
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programas
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\ProgramData\Menu Iniciar
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\ProgramData\Documentos
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\ProgramData\Dados de Aplicativos
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Program Files\Common Files\Sistema
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Program Files\Arquivos Comuns
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Documents and Settings
2024-08-09 15:50 - 2024-08-09 15:50 - 000000000 _SHDL C:\Arquivos de Programas
2024-08-09 15:49 - 2024-08-12 15:04 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-08-09 15:49 - 2024-08-12 14:10 - 000008192 ___SH C:\DumpStack.log.tmp
2024-08-09 15:49 - 2024-08-12 14:10 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-08-09 15:49 - 2024-08-11 19:26 - 000000000 ____D C:\Windows\Panther
2024-08-09 15:49 - 2024-08-10 01:58 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-08-09 15:49 - 2024-08-10 01:52 - 000003674 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-08-09 15:49 - 2024-08-10 01:52 - 000003550 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-08-09 15:49 - 2024-08-09 23:50 - 000438912 _____ C:\Windows\system32\FNTCACHE.DAT
2024-08-09 15:49 - 2024-08-09 19:26 - 000000000 ____D C:\Windows\system32\Drivers\wd
2024-08-09 15:49 - 2024-08-09 15:49 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2024-08-09 15:49 - 2024-08-09 15:49 - 000000000 ____D C:\Windows\ServiceProfiles

==================== Três meses (modificados) ==================

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2024-08-12 17:53 - 2019-12-07 06:13 - 000000000 ____D C:\Windows\INF
2024-08-12 17:52 - 2019-12-07 06:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-08-12 15:53 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\NDF
2024-08-12 15:15 - 2019-12-07 06:03 - 000000000 ____D C:\Windows\CbsTemp
2024-08-12 14:16 - 2019-12-07 11:54 - 000717080 _____ C:\Windows\system32\prfh0416.dat
2024-08-12 14:16 - 2019-12-07 11:54 - 000141220 _____ C:\Windows\system32\prfc0416.dat
2024-08-12 14:10 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\ServiceState
2024-08-12 14:09 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\AppReadiness
2024-08-12 14:09 - 2019-12-07 06:03 - 000524288 _____ C:\Windows\system32\config\BBI
2024-08-12 14:02 - 2019-12-07 06:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-08-12 11:16 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\appcompat
2024-08-10 18:47 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\setup
2024-08-09 23:51 - 2019-12-07 06:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-08-09 23:49 - 2023-12-03 23:53 - 000000000 ____D C:\Windows\InboxApps
2024-08-09 23:49 - 2019-12-07 11:57 - 000000000 ____D C:\Program Files\Windows Portable Devices
2024-08-09 23:49 - 2019-12-07 11:57 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2024-08-09 23:49 - 2019-12-07 11:57 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2024-08-09 23:49 - 2019-12-07 11:57 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ___SD C:\Windows\SysWOW64\F12
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ___SD C:\Windows\system32\UNP
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ___SD C:\Windows\system32\F12
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ___RD C:\Windows\PrintDialog
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\SystemResources
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\ShellExperiences
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\oobe
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\migwiz
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\Dism
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\DDFs
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\appraiser
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\ShellExperiences
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\ShellComponents
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\Provisioning
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2024-08-09 23:49 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\bcastdvr
2024-08-09 23:49 - 2019-12-07 06:03 - 000000000 ____D C:\Windows\servicing
2024-08-09 20:29 - 2019-12-07 06:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2024-08-09 19:26 - 2019-12-07 06:14 - 000000000 ____D C:\Program Files\Windows Defender
2024-08-09 19:17 - 2019-12-07 06:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2024-08-09 19:15 - 2023-12-03 23:53 - 000000000 ____D C:\Windows\SystemTemp
2024-08-09 17:41 - 2019-12-07 06:03 - 000032768 _____ C:\Windows\system32\config\ELAM
2024-08-09 17:33 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\LiveKernelReports
2024-08-09 16:40 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\Drivers\DriverData
2024-08-09 15:55 - 2019-12-07 06:14 - 000000000 ____D C:\ProgramData\USOPrivate
2024-08-09 15:53 - 2019-12-07 11:55 - 000000000 ____D C:\Windows\system32\FxsTmp
2024-08-09 15:53 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\spool
2024-08-09 15:51 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2024-08-09 15:50 - 2019-12-07 06:14 - 000000000 ____D C:\Program Files\Windows NT
2024-08-09 15:49 - 2019-12-07 06:14 - 000028672 _____ C:\Windows\system32\config\BCD-Template

==================== SigCheckExt =========================

2024-08-10 18:47 - 2024-08-10 18:47 - 015434240 _____ C:\Users\Raphael\Downloads\certisign10.6-x64-10.6.exe
2024-08-12 17:09 - 2024-08-12 17:09 - 002397184 _____ (Farbar) C:\Users\Raphael\Downloads\FRST64.exe
2024-08-09 16:43 - 2024-08-09 16:43 - 000394240 _____ (Google Inc.) C:\Users\Raphael\Downloads\gcapi.dll
2024-08-12 12:40 - 2024-08-12 12:40 - 066465344 _____ (Certisign Certificadora Digital ) C:\Users\Raphael\Downloads\Setup_desktopID.exe

==================== SigCheck ============================

(Não há correção automática para arquivos que não passaram na verificação.)


==================== BCD ================================

Gerenciador de Inicialização de Firmware
----------------------------------------
identificador           {fwbootmgr}
displayorder            {bootmgr}
                        {650b9e13-567f-11ef-abc0-eeb011bc16b2}
                        {650b9e14-567f-11ef-abc0-eeb011bc16b2}
                        {650b9e15-567f-11ef-abc0-eeb011bc16b2}
                        {650b9e16-567f-11ef-abc0-eeb011bc16b2}
timeout                 0

Gerenciador de Inicialização do Windows
---------------------------------------
identificador           {bootmgr}
device                  partition=\Device\HarddiskVolume1
path                    \EFI\Microsoft\Boot\bootmgfw.efi
description             Windows Boot Manager
locale                  pt-BR
inherit                 {globalsettings}
default                 {current}
resumeobject            {650b9e19-567f-11ef-abc0-eeb011bc16b2}
displayorder            {current}
toolsdisplayorder       {memdiag}
timeout                 30

Aplicativo de Firmware (101fffff)
---------------------------------
identificador           {650b9e13-567f-11ef-abc0-eeb011bc16b2}
description             EFI USB Device

Aplicativo de Firmware (101fffff)
---------------------------------
identificador           {650b9e14-567f-11ef-abc0-eeb011bc16b2}
description             EFI DVD/CDROM

Aplicativo de Firmware (101fffff)
---------------------------------
identificador           {650b9e15-567f-11ef-abc0-eeb011bc16b2}
description             EFI Network

Aplicativo de Firmware (101fffff)
---------------------------------
identificador           {650b9e16-567f-11ef-abc0-eeb011bc16b2}
description             INTEL SSDPEKNW512G8L           

Carregador de Inicialização do Windows
--------------------------------------
identificador           {current}
device                  partition=C:
path                    \Windows\system32\winload.efi
description             Windows 10
locale                  pt-BR
inherit                 {bootloadersettings}
recoverysequence        {650b9e1b-567f-11ef-abc0-eeb011bc16b2}
displaymessageoverride  Recovery
recoveryenabled         Yes
isolatedcontext         Yes
allowedinmemorysettings 0x15000075
osdevice                partition=C:
systemroot              \Windows
resumeobject            {650b9e19-567f-11ef-abc0-eeb011bc16b2}
nx                      OptIn
bootmenupolicy          Standard

Carregador de Inicialização do Windows
--------------------------------------
identificador           {650b9e1b-567f-11ef-abc0-eeb011bc16b2}
device                  ramdisk=[\Device\HarddiskVolume4]\Recovery\WindowsRE\Winre.wim,{650b9e1c-567f-11ef-abc0-eeb011bc16b2}
path                    \windows\system32\winload.efi
description             Windows Recovery Environment
locale                  pt-br
inherit                 {bootloadersettings}
displaymessage          Recovery
osdevice                ramdisk=[\Device\HarddiskVolume4]\Recovery\WindowsRE\Winre.wim,{650b9e1c-567f-11ef-abc0-eeb011bc16b2}
systemroot              \windows
nx                      OptIn
bootmenupolicy          Standard
winpe                   Yes

Continuar da Hibernação
-----------------------
identificador           {650b9e19-567f-11ef-abc0-eeb011bc16b2}
device                  partition=C:
path                    \Windows\system32\winresume.efi
description             Windows Resume Application
locale                  pt-BR
inherit                 {resumeloadersettings}
recoverysequence        {650b9e1b-567f-11ef-abc0-eeb011bc16b2}
recoveryenabled         Yes
isolatedcontext         Yes
allowedinmemorysettings 0x15000075
filedevice              partition=C:
filepath                \hiberfil.sys
bootmenupolicy          Standard
debugoptionenabled      No

Testador de Memória do Windows
------------------------------
identificador           {memdiag}
device                  partition=\Device\HarddiskVolume1
path                    \EFI\Microsoft\Boot\memtest.efi
description             Diagnóstico de Memória do Windows
locale                  pt-BR
inherit                 {globalsettings}
badmemoryaccess         Yes

Configurações de EMS
--------------------
identificador           {emssettings}
bootems                 No

Configurações do Depurador
--------------------------
identificador           {dbgsettings}
debugtype               Local

Defeitos de RAM
---------------
identificador           {badmemory}

Configurações Globais
---------------------
identificador           {globalsettings}
inherit                 {dbgsettings}
                        {emssettings}
                        {badmemory}

Configurações do Carregador de Inicialização
--------------------------------------------
identificador           {bootloadersettings}
inherit                 {globalsettings}
                        {hypervisorsettings}

Configurações do Hypervisor
---------------------------
identificador           {hypervisorsettings}
hypervisordebugtype     Serial
hypervisordebugport     1
hypervisorbaudrate      115200

Configurações do Carregador de Retorno
--------------------------------------
identificador           {resumeloadersettings}
inherit                 {globalsettings}

Opções de dispositivo
---------------------
identificador           {650b9e1c-567f-11ef-abc0-eeb011bc16b2}
description             Windows Recovery
ramdisksdidevice        partition=\Device\HarddiskVolume4
ramdisksdipath          \Recovery\WindowsRE\boot.sdi

==================== Fim de FRST.txt ========================


E esse é o "Shortcut.txt":

Resultado da análise no atalho de usuários (x64) Versão: 12-08.2024
Executado por Raphael (12-08-2024 17:58:54)
Executando a partir de C:\Users\Raphael\Downloads
Modo da Inicialização: Normal

==================== Atalhos =============================

(As entradas podem ser listadas para serem restauradas ou removidas.)


Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk -> C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk -> C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navegação privativa do Firefox.lnk -> C:\Program Files\Mozilla Firefox\private_browsing.exe (Mozilla Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Program Files\Microsoft OneDrive\OneDrive.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook (classic).lnk -> C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk -> C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk -> C:\Program Files\Microsoft Office\root\Office16\MSPUB.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk -> C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SafeNet\SafeNet Authentication Client\SafeNet Authentication Client Tools.lnk -> C:\Program Files\SafeNet\Authentication\SAC\x64\SACTools.exe (Gemalto)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SafeNet\SafeNet Authentication Client\SafeNet Authentication Client.lnk -> C:\Program Files\SafeNet\Authentication\SAC\x64\SACMonitor.exe (Gemalto)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Desinstalar o Revo Uninstaller.lnk -> C:\Program Files\VS Revo Group\Revo Uninstaller\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Revo Uninstaller Help.lnk -> C:\Program Files\VS Revo Group\Revo Uninstaller\Revo Uninstaller Help.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Revo Uninstaller.lnk -> C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe (VS Revo Group)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk -> C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\lenovo\System Update.lnk -> C:\Program Files (x86)\Lenovo\System Update\tvsu.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configurar Java.lnk -> C:\Program Files (x86)\Java\jre1.8.0_421\bin\javacpl.exe (Oracle Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ferramentas do Microsoft Office\Preferências de Idioma do Office.lnk -> C:\Program Files\Microsoft Office\root\Office16\SETLANG.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyDesk\AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\Windows\SysWOW64\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk -> C:\Windows\System32\RecoveryDrive.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Registry Editor.lnk -> C:\Windows\regedit.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk -> C:\Windows\System32\quickassist.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\Windows\System32\psr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk -> C:\Program Files\7-Zip\7zFM.exe (Igor Pavlov)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk -> C:\Program Files\7-Zip\7-zip.chm ()
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\Adobe Acrobat.lnk -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe (Adobe Systems Incorporated)
Shortcut: C:\Users\Public\Desktop\AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH)
Shortcut: C:\Users\Public\Desktop\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC)
Shortcut: C:\Users\Public\Desktop\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\Revo Uninstaller.lnk -> C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe (VS Revo Group)
Shortcut: C:\Users\Raphael\Links\Desktop.lnk -> C:\Users\Raphael\OneDrive\Área de Trabalho ()
Shortcut: C:\Users\Raphael\Links\Downloads.lnk -> C:\Users\Raphael\Downloads ()
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Desinstalar Lenovo Service Bridge.lnk -> C:\Users\Raphael\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\unins000.exe ()
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Service Bridge.lnk -> C:\Users\Raphael\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSB.exe (Lenovo Group Limited)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\SendTo\Transferência de Arquivo Bluetooth.LNK -> C:\Windows\System32\fsquirt.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Raphael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Tombstones\Driver Booster (3).lnk -> C:\Program Files (x86)\IObit\Driver Booster\11.6.0\DriverBooster.exe (Nenhum Arquivo)
Shortcut: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation)


ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sticky Notes (Preview).lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE (Microsoft Corporation) -> /memoryWindow start
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /7
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH) ->  --control
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Sobre o Java.lnk -> C:\Program Files (x86)\Java\jre1.8.0_421\bin\javacpl.exe (Oracle Corporation) -> -tab about
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Verificar Atualizações.lnk -> C:\Program Files (x86)\Java\jre1.8.0_421\bin\javacpl.exe (Oracle Corporation) -> -tab update
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyDesk\Uninstall AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH) ->  --uninstall
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools
ShortcutWithArgument: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Raphael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) -> --profile-directory=Default
ShortcutWithArgument: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus
ShortcutWithArgument: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo
ShortcutWithArgument: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep
ShortcutWithArgument: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes
ShortcutWithArgument: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\Raphael\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}


InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Revo Uninstaller na Web.url -> URL: hxxps://www.revouninstaller.com/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Obter Ajuda.url -> URL: hxxps://java.com/help
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visite Java.com.url -> URL: hxxps://java.com/
InternetURL: C:\Users\Raphael\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142

==================== Fim de Shortcut.txt =============================


Não sei se estou postando certo ou não e se devo explicar mais! Mas é isso!
Obrigado!
0

Pedido de Análise de Log

Peço que por favor, analisem esses logs, os sintomas são:

 - Lentidão do PC, sobretudo quando estou conectado na internet.

 - Mensagens do tipo pop-up nos browsers dizendo que estou infectado.

 - Mensagens do tipo pop-up nos browsers dizendo "confirm you are not a robot".
 
 - Sempre quando tento copiar algum video do pendrive para o HD, o video sempre se corrompe e diz que nao é possivel renderizar. (isso só começou a ocorrer depois da infecção).


Resultado do análise da Farbar Recovery Scan Tool (FRST) (x64) Versão: 28.07.2024
Executado por Neo (administrador) em MATRIX2025 (30-07-2024 17:31:07)
Executando a partir de C:\Users\Net\Desktop\FRST64.exe
Perfis Carregados: Neo & Net
Plataforma: Microsoft Windows 11 Pro Versão 23H2 22631.3880 (X64) Idioma: Português (Brasil)
Navegador padrão: FF
Modo da Inicialização: Normal

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.16300.20.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe -&gt (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.113\msedgewebview2.exe <6>
(DriverStore\FileRepository\u0360470.inf_amd64_35c64671e7fac064\B360357\atiesrxx.exe -&gt (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0360470.inf_amd64_35c64671e7fac064\B360357\atieclxx.exe
(services.exe -&gt (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0360470.inf_amd64_35c64671e7fac064\B360357\atiesrxx.exe
(services.exe -&gt (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpDefenderCoreService.exe
(services.exe -&gt (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MsMpEng.exe
(services.exe -&gt (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\NisSrv.exe
(svchost.exe -&gt (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2429.10.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.16300.20.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
(svchost.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe -&gt (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe
Falha ao acessar processo -> vmmemCmZygote

==================== Registro (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restrição <==== ATENÇÃO
HKU\S-1-5-21-1875411646-3612572813-2532316385-1001\...\Run: [OneDrive] => "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background (Nenhum Arquivo)
HKU\S-1-5-21-1875411646-3612572813-2532316385-1001\...\Run: [MicrosoftEdgeAutoLaunch_6431A1DCEFAE3C8A629DDE1D8F63B1E2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3814848 2024-07-25] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Print\Monitors\HP E111 Status Monitor: C:\Windows\system32\hpinkstsE111LM.dll [393352 2017-04-14] (Hewlett Packard -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\127.0.6533.73\Installer\chrmstp.exe [2024-07-29] (Google LLC -> Google LLC)
GroupPolicy: Restrição ? <==== ATENÇÃO
Policies: C:\ProgramData\NTUSER.pol: Restrição <==== ATENÇÃO
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restrição <==== ATENÇÃO

==================== Tarefas Agendadas (Whitelisted) =================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

Task: {F1A88049-AE1D-4DC1-A683-540657FA470F} - System32\Tasks\ASC_PerformanceMonitor => "C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe"  -> C:\Program Files (x86)\IObit\Advanced SystemCare\\/Task
Task: {C393285C-D2AE-4914-9652-01DC8B442724} - System32\Tasks\ASC_SkipUac_Neo => "C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe"  -> C:\Program Files (x86)\IObit\Advanced SystemCare\\/SkipUac
Task: {F554253E-A124-42D1-A064-FA7C73119D0B} - System32\Tasks\EaseUS_RecExperts_Web => "C:\Program Files (x86)\EaseUS\RecExperts\bin\TaskSchedulerWeb.exe"  /skipuac (Nenhum Arquivo)
Task: {678C5E45-CD15-48E5-9B09-94B43DD9B02B} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem128.0.6597.0{9C4070BE-2EC9-4547-821F-3E3C2885777C} => C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe [4889704 2024-07-15] (Google LLC -> Google LLC)
Task: {ED1858B7-DC2B-4E8D-86A9-3609DCE465D3} - System32\Tasks\infatica_p2b => "C:\Program Files (x86)\Infatica P2B\infatica_agent.exe"  (Nenhum Arquivo)
Task: {D8BF4758-CB2C-4C07-8B61-1399A4C1B5E8} - System32\Tasks\iTop easter Task (One-Time) => "C:\Program Files (x86)\iTop VPN\Pub\itopeasterp24.exe"  -> C:\Program Files (x86)\iTop VPN\Pub\\/easter
Task: {C1710EA8-762B-4791-B028-CE5BFA49E5DC} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2113024 2024-03-11] () [Arquivo não assinado]
Task: {8C385297-326F-485E-A82E-7F80BC14AE62} - System32\Tasks\Microsoft\Windows\Maintenance\SystemMonitor => C:\Users\Neo\AppData\Roaming\systemmonitor\sysmon.exe [223232 2024-04-23] () [Arquivo não assinado] <==== ATENÇÃO
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (Nenhum Arquivo)
Task: {08B0F983-378F-4794-A296-D852B191E91A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpCmdRun.exe [1678960 2024-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {66D8EC9A-A05A-4D83-9E06-7001EF19CBA0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpCmdRun.exe [1678960 2024-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D100AA1E-6F94-47E7-B683-F4B9EAE0744E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpCmdRun.exe [1678960 2024-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B73A793D-ACC3-4C20-B893-7F90DDCDFC55} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpCmdRun.exe [1678960 2024-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {812D95D5-C701-4F96-B156-192CBD8C56B5} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1875411646-3612572813-2532316385-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [677448 2024-07-27] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (a entrada de dados tem 6 mais caracteres).
Task: {9010676D-AEE6-446D-AE0C-6BB34225EA9E} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1875411646-3612572813-2532316385-1002 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [677448 2024-07-27] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (a entrada de dados tem 6 mais caracteres).
Task: {975FAB1A-61A5-4B7A-B598-ED9FD7A8E815} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34376 2024-07-27] (Mozilla Corporation -> Mozilla Foundation)
Task: {82B60921-8209-418F-BE55-A5B6DE98656F} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1875411646-3612572813-2532316385-1001 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  /reporting (Nenhum Arquivo)
Task: {25EBAD64-9BE8-410A-8565-2BB0F986AB56} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1875411646-3612572813-2532316385-1002 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  /reporting (Nenhum Arquivo)
Task: {678A82B4-8A27-4E7B-8D9C-3D265EEC416A} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1875411646-3612572813-2532316385-1001 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (Nenhum Arquivo)
Task: {CF6D53BE-815C-4884-ADAC-883A65A8812D} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1875411646-3612572813-2532316385-1002 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (Nenhum Arquivo)
Task: {C3B2C5AC-5259-4AD7-B8CD-5735873B5BA3} - System32\Tasks\Uninstaller_SkipUac_Net => "C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe"  -> C:\Program Files (x86)\IObit\IObit Uninstaller\\/UninstallExplorer
Task: {D19385A9-8BFD-4DD5-B5BC-FD54E999FCF5} - System32\Tasks\WpsExternal_Net_20240708112545 => C:\Users\Net\AppData\Local\Kingsoft\WPS Office\12.2.0.17153\office6\wpscloudsvr.exe [1036176 2024-07-08] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd) -> /wpscloudlaunch /run_plugin /plugin_name=ktaskschdtool /plugin_entry=ktaskschdtool.dll /task=wpsexternal /launchtask /ver=1.0 /start_from=task_external
Task: {1709E13D-1B3E-4BED-A700-A177BFCAFA9D} - System32\Tasks\WpsUpdateTask_Net => C:\Users\Net\AppData\Local\Kingsoft\WPS Office\12.2.0.17153\office6\wpsupdate.exe [1550224 2024-07-08] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)

(Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.)

Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\Parameters: [DhcpNameServer] 181.213.132.6 181.213.132.7
Tcpip\..\Interfaces\{175c997e-22b0-4037-83bc-f2621c323028}: [DhcpNameServer] 181.213.132.6 181.213.132.7

Edge:
=======
Edge Profile: C:\Users\Neo\AppData\Local\Microsoft\Edge\User Data\Default [2024-07-30]
Edge Extension: (Documentos Google off-line) - C:\Users\Neo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-05]
Edge Extension: (Edge relevant text changes) - C:\Users\Neo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-03-05]

FireFox:
========
FF DefaultProfile: 6ur4hfrv.default
FF ProfilePath: C:\Users\Neo\AppData\Roaming\Mozilla\Firefox\Profiles\6ur4hfrv.default [2024-03-05]
FF ProfilePath: C:\Users\Neo\AppData\Roaming\Mozilla\Firefox\Profiles\bckhy9yn.default-release [2024-07-30]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT PDF READER\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT PDF READER\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT PDF READER\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT PDF READER\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT PDF READER\plugins\npFoxitPDFReaderPlugin.dll [2024-05-23] (FOXIT SOFTWARE INC. -> Foxit Corporation)

Chrome:
=======
CHR Profile: C:\Users\Neo\AppData\Local\Google\Chrome\User Data\Default [2024-07-30]
CHR Extension: (Documentos Google off-line) - C:\Users\Neo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-03]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Neo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-03-16]

==================== Serviços (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpDefenderCoreService.exe [1377416 2024-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [522184 2024-05-15] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [794544 2024-05-02] (Oracle America, Inc. -> Oracle and/or its affiliates)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\NisSrv.exe [3236728 2024-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MsMpEng.exe [133688 2024-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 wpscloudsvr; C:\Program Files (x86)\Kingsoft\office6\wpscloudsvr.exe [965520 2024-03-06] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
S3 Browser; %SystemRoot%\System32\browser.dll [X]
S2 ListaryServiceV2; "C:\Program Files\Listary\Listary.Service.exe" [X]
S2 ONLYOFFICE Update Service; "C:\Program Files\ONLYOFFICE\DesktopEditors\updatesvc.exe" [X]
S2 uhssvc; "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe" [X]

===================== Drivers (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [544768 2023-12-04] (Microsoft Corporation) [Arquivo não assinado]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [188416 2023-12-04] (Microsoft Corporation) [Arquivo não assinado]
R0 fse; C:\Windows\System32\drivers\fse.sys [218608 2024-07-15] (Microsoft Windows -> Microsoft Corporation)
R3 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [254352 2024-05-02] (Oracle Corporation -> Oracle and/or its affiliates)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [265224 2024-05-02] (Oracle Corporation -> Oracle and/or its affiliates)
R1 VBoxSup; C:\Windows\system32\DRIVERS\VBoxSup.sys [1063752 2024-05-02] (Oracle Corporation -> Oracle and/or its affiliates)
S3 vmbusproxy; C:\Windows\system32\drivers\vmbusproxy.sys [94208 2024-07-15] (Microsoft Windows -> )
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [21968 2024-07-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [602520 2024-07-15] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105864 2024-07-15] (Microsoft Windows -> Microsoft Corporation)
S3 cpuz154; \??\C:\Windows\temp\cpuz154\cpuz154_x64.sys [X] <==== ATENÇÃO

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um mês (criados) (Whitelisted) =========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2024-07-30 17:31 - 2024-07-30 17:32 - 000016690 _____ C:\Users\Net\Desktop\FRST.txt
2024-07-30 17:30 - 2024-07-30 17:31 - 000000000 ____D C:\FRST
2024-07-30 17:29 - 2024-07-30 17:29 - 002397184 _____ (Farbar) C:\Users\Net\Desktop\FRST64.exe
2024-07-30 17:11 - 2024-07-30 17:11 - 000726848 _____ C:\Windows\system32\prfh0416.dat
2024-07-30 17:11 - 2024-07-30 17:11 - 000141922 _____ C:\Windows\system32\prfc0416.dat
2024-07-30 16:57 - 2024-07-30 16:57 - 000000428 __RSH C:\ProgramData\ntuser.pol
2024-07-30 16:47 - 2024-07-30 16:47 - 000003320 _____ C:\Users\Net\Desktop\ZHP CLEAN.txt
2024-07-30 16:32 - 2024-07-30 16:33 - 000003125 _____ C:\Users\Net\Desktop\Novo(a) Documento de Texto (5).txt
2024-07-30 12:35 - 2024-07-30 12:35 - 003365064 _____ (Nicolas Coolman) C:\Users\Net\Desktop\ZHPCleaner.exe
2024-07-30 10:46 - 2024-07-30 10:50 - 1729709205 _____ C:\Users\Net\Downloads\latest.zip
2024-07-29 23:35 - 2024-07-29 23:35 - 000000000 ____D C:\Users\Net\AppData\Local\Eraser 6
2024-07-29 21:36 - 2024-07-29 21:36 - 000000000 ____D C:\Users\Neo\AppData\Local\Eraser 6
2024-07-29 21:29 - 2024-07-29 21:31 - 008843096 _____ (The Eraser Project) C:\Users\Net\Downloads\Eraser 6.2.0.2994.exe
2024-07-29 17:45 - 2024-07-29 17:45 - 000000000 ____D C:\Users\Net\Downloads\nome da rosa
2024-07-28 13:24 - 2024-07-28 13:25 - 000000000 ____D C:\Users\Net\AppData\Local\SumatraPDF
2024-07-27 22:20 - 2024-07-27 22:24 - 000000000 ____D C:\Users\Net\AppData\Roaming\SwifDooPDFData
2024-07-27 22:01 - 2024-07-28 03:14 - 000000000 ____D C:\Program Files\Mozilla Firefox
2024-07-25 22:53 - 2024-07-25 22:53 - 009892032 _____ (Cybertron Software Co., Ltd. ) C:\Users\Neo\Downloads\privacy-eraser-setup (2).exe
2024-07-25 22:53 - 2024-07-25 22:53 - 009892032 _____ (Cybertron Software Co., Ltd. ) C:\Users\Neo\Downloads\privacy-eraser-setup (1).exe
2024-07-25 17:57 - 2024-07-25 17:57 - 020220144 _____ (pendrivelinux.com) C:\Users\Neo\Downloads\YUMI-exFAT-1.0.2.7.exe
2024-07-25 16:16 - 2024-07-25 16:17 - 003365064 _____ (Nicolas Coolman) C:\Users\Neo\Downloads\ZHPCleaner.exe
2024-07-25 16:16 - 2024-07-25 16:17 - 003365064 _____ (Nicolas Coolman) C:\Users\Neo\Desktop\ZHPCleaner.exe
2024-07-24 17:27 - 2024-07-24 17:27 - 000240544 _____ C:\Users\Net\Downloads\trisquel_11.0.1_amd64.iso.torrent
2024-07-24 17:26 - 2024-07-24 17:26 - 000123787 _____ C:\Users\Net\Downloads\trisquel-mini_11.0.1_amd64.iso.torrent
2024-07-24 17:23 - 2024-07-24 17:23 - 000011541 _____ C:\Users\Net\Documents\Distros PC Fraco.xlsx
2024-07-23 20:53 - 2024-07-24 19:56 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2024-07-19 21:00 - 2024-07-19 21:00 - 036426934 _____ (Easy2Boot ) C:\Users\Net\Downloads\Easy2Boot_v2.20.exe
2024-07-18 22:55 - 2024-07-28 13:40 - 000000000 ____D C:\Users\Net\AppData\Roaming\Kodi
2024-07-18 22:48 - 2024-07-18 22:48 - 076923883 _____ (XBMC Foundation) C:\Users\Net\Downloads\kodi-21.0-Omega-x64.exe
2024-07-17 14:14 - 2024-07-17 14:14 - 000000000 ____D C:\Users\Net\Downloads\winUSB
2024-07-15 21:03 - 2024-07-17 18:28 - 000000617 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2024-07-15 17:52 - 2024-07-15 17:52 - 000000000 ___SD C:\Windows\system32\Containers
2024-07-15 17:52 - 2024-07-15 17:52 - 000000000 ____D C:\Windows\system32\HvsiSettingsProviders
2024-07-15 15:44 - 2024-07-15 16:22 - 000000000 ____D C:\Users\Net\VirtualBox VMs
2024-07-15 15:43 - 2024-07-15 16:22 - 000000000 ____D C:\Users\Net\.VirtualBox
2024-07-15 12:14 - 2024-07-15 15:41 - 000000000 ____D C:\Users\Neo\VirtualBox VMs
2024-07-15 12:13 - 2024-07-15 15:40 - 000000000 ____D C:\Users\Neo\.VirtualBox
2024-07-15 12:12 - 2024-07-15 12:12 - 000001149 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
2024-07-15 12:12 - 2024-07-15 12:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2024-07-15 12:12 - 2024-07-15 12:12 - 000000000 ____D C:\Program Files\Oracle
2024-07-15 12:12 - 2024-05-02 03:10 - 001063752 _____ (Oracle and/or its affiliates) C:\Windows\system32\Drivers\VBoxSup.sys
2024-07-15 12:12 - 2024-05-02 03:10 - 000203912 _____ (Oracle and/or its affiliates) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2024-07-15 12:11 - 2024-07-15 12:11 - 109700144 _____ (Oracle and/or its affiliates) C:\Users\Net\Downloads\VirtualBox-7.0.18-162988-Win.exe
2024-07-13 13:55 - 2024-07-13 13:55 - 000305248 _____ C:\Windows\system32\FNTCACHE.DAT
2024-07-11 18:53 - 2024-07-11 18:53 - 000000000 ____D C:\Users\Net\Documents\Zoom
2024-07-11 03:26 - 2024-07-11 03:26 - 000248241 _____ C:\Users\Net\Documents\favoritos_11_07_2024.html
2024-07-10 20:20 - 2024-07-10 20:20 - 000000000 ____D C:\Users\Net\AppData\Local\Sentry
2024-07-10 19:59 - 2024-07-10 19:59 - 000000000 ____D C:\Users\Net\AppData\Local\Opera Software
2024-07-10 19:58 - 2024-07-10 19:58 - 000000000 ____D C:\Users\Net\AppData\Roaming\Opera Software
2024-07-10 17:08 - 2024-07-10 17:08 - 000025684 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-07-10 17:07 - 2024-07-10 17:07 - 000025684 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2024-07-10 16:55 - 2024-07-10 17:01 - 000000000 ___HD C:\$WinREAgent
2024-07-10 15:53 - 2024-07-10 15:54 - 000000000 ____D C:\Users\Net\Downloads\TORRENTS
2024-07-08 11:25 - 2024-07-08 11:25 - 000004050 _____ C:\Windows\system32\Tasks\WpsExternal_Net_20240708112545
2024-07-08 11:25 - 2024-07-08 11:25 - 000003620 _____ C:\Windows\system32\Tasks\WpsUpdateTask_Net
2024-07-06 10:52 - 2024-07-06 10:52 - 001366256 _____ C:\Users\Net\Documents\060724-Bookmarks.html
2024-07-05 22:30 - 2024-07-05 22:30 - 001401742 _____ C:\Users\Net\Documents\050724-bookmarks.html
2024-07-05 21:35 - 2024-07-05 21:35 - 000247504 _____ C:\Users\Net\Documents\favoritos_05_07_2024.html
2024-07-03 11:06 - 2024-07-30 16:46 - 000010043 _____ C:\Users\Neo\Desktop\ZHPCleaner (R).html
2024-07-03 11:06 - 2024-07-30 16:46 - 000003284 _____ C:\Users\Neo\Desktop\ZHPCleaner (R).txt
2024-07-03 11:03 - 2024-07-30 16:25 - 000009764 _____ C:\Users\Neo\Desktop\ZHPCleaner (S).html
2024-07-03 11:03 - 2024-07-30 16:25 - 000003114 _____ C:\Users\Neo\Desktop\ZHPCleaner (S).txt
2024-07-03 10:48 - 2024-07-25 16:17 - 000000873 _____ C:\Users\Neo\Desktop\ZHPCleaner.lnk
2024-07-01 05:54 - 2023-01-08 16:59 - 008777005 _____ C:\Users\Net\Documents\Glass Clean Tool.mp4

==================== Um mês (modificados) ==================

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2024-07-30 20:07 - 2024-03-05 19:56 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-07-30 20:06 - 2024-03-14 14:49 - 000001134 _____ C:\Windows\system32\config\VSMIDK
2024-07-30 20:06 - 2024-03-05 19:56 - 000012288 ___SH C:\DumpStack.log.tmp
2024-07-30 20:06 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\ServiceState
2024-07-30 17:20 - 2024-03-05 20:09 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-07-30 17:20 - 2022-05-07 02:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-07-30 17:18 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\SystemTemp
2024-07-30 17:11 - 2024-03-05 17:09 - 001679878 _____ C:\Windows\system32\PerfStringBackup.INI
2024-07-30 17:11 - 2022-05-07 02:22 - 000000000 ____D C:\Windows\INF
2024-07-30 16:57 - 2024-03-05 17:07 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2024-07-30 16:57 - 2022-05-07 02:17 - 000524288 _____ C:\Windows\system32\config\BBI
2024-07-30 16:49 - 2024-03-05 19:56 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-07-30 16:46 - 2024-03-06 21:04 - 000000000 ____D C:\Users\Neo\AppData\Roaming\ZHP
2024-07-30 14:58 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\AppReadiness
2024-07-30 12:47 - 2024-03-06 16:31 - 000000000 ____D C:\Users\Net\AppData\Roaming\qBittorrent
2024-07-30 10:43 - 2024-03-10 19:17 - 000000000 ____D C:\Users\Net\AppData\Roaming\Telegram Desktop
2024-07-29 20:30 - 2024-03-13 22:11 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-07-29 20:07 - 2024-03-05 20:19 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1875411646-3612572813-2532316385-1002
2024-07-29 20:07 - 2024-03-05 20:19 - 000003366 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1875411646-3612572813-2532316385-1002
2024-07-29 20:07 - 2024-03-05 20:19 - 000002383 _____ C:\Users\Net\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-07-29 19:46 - 2024-03-06 16:41 - 000000000 ____D C:\Users\Net\AppData\Roaming\HandBrake
2024-07-29 09:15 - 2024-03-05 19:56 - 000003536 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-07-29 09:15 - 2024-03-05 19:56 - 000003412 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-07-28 21:13 - 2024-03-05 20:18 - 000000000 ____D C:\Users\Net
2024-07-28 21:01 - 2024-03-05 17:10 - 000000000 ____D C:\Users\Neo
2024-07-28 19:33 - 2024-03-12 15:42 - 000000000 ____D C:\Users\Net\AppData\Local\CrashDumps
2024-07-28 19:28 - 2024-06-29 19:39 - 000000000 ____D C:\Users\Net\AppData\Roaming\Grammarly
2024-07-28 19:22 - 2024-03-13 17:19 - 000000000 ____D C:\Users\Neo\AppData\Roaming\MPC-HC
2024-07-28 19:03 - 2024-03-28 08:54 - 000000000 ___HD C:\Users\Net\WPS Cloud Files
2024-07-28 13:42 - 2024-03-22 16:18 - 000001590 _____ C:\Users\Net\Desktop\E-book SELLPAGE.txt
2024-07-28 03:14 - 2024-03-05 20:08 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-07-27 23:46 - 2024-03-06 04:49 - 000000000 ____D C:\Users\Net\AppData\Local\D3DSCache
2024-07-27 22:21 - 2024-03-05 20:09 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2024-07-27 22:20 - 2024-03-05 20:08 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-07-27 15:29 - 2024-05-18 16:48 - 000000000 ____D C:\Users\Net\AppData\Roaming\obs-studio
2024-07-27 15:20 - 2024-05-18 16:48 - 000000000 ____D C:\ProgramData\obs-studio
2024-07-27 13:28 - 2022-05-07 02:24 - 000000000 ___HD C:\Program Files\WindowsApps
2024-07-25 22:52 - 2024-03-13 14:25 - 000000000 ____D C:\Users\Neo\AppData\Local\CrashDumps
2024-07-25 11:51 - 2024-04-26 16:27 - 000000000 ____D C:\Users\Net\AppData\Roaming\Microsoft\MMC
2024-07-23 21:28 - 2024-03-29 20:44 - 000000000 ____D C:\Users\Net\Downloads\Telegram Desktop
2024-07-23 21:03 - 2024-03-07 14:38 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2024-07-22 16:02 - 2024-03-09 18:24 - 000000000 ____D C:\Users\Public\Foxit Software
2024-07-21 19:10 - 2024-03-06 16:41 - 000000000 ____D C:\ProgramData\Package Cache
2024-07-19 08:12 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\LiveKernelReports
2024-07-18 02:20 - 2024-03-05 17:14 - 000000000 ____D C:\Users\Neo\AppData\Local\D3DSCache
2024-07-17 18:29 - 2024-03-05 20:18 - 000000000 ____D C:\Users\Net\AppData\Local\Packages
2024-07-15 18:08 - 2022-05-07 02:24 - 000000000 ____D C:\ProgramData\USOPrivate
2024-07-15 18:04 - 2024-03-05 19:56 - 000000000 ____D C:\Windows\system32\Drivers\wd
2024-07-15 16:42 - 2022-05-07 02:17 - 000000000 ____D C:\Windows\CbsTemp
2024-07-15 16:41 - 2024-06-12 12:35 - 001090928 _____ (Microsoft Corporation) C:\Windows\system32\WindowsSandbox.exe
2024-07-15 16:41 - 2024-06-12 12:35 - 000774144 _____ (Microsoft Corporation) C:\Windows\system32\gns.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000706016 _____ (Microsoft Corporation) C:\Windows\system32\vmusrv.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000628208 _____ (Microsoft Corporation) C:\Windows\system32\vmuidevices.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000628192 _____ (Microsoft Corporation) C:\Windows\system32\vmserial.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000554464 _____ (Microsoft Corporation) C:\Windows\system32\vmpmem.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000517488 _____ (Microsoft Corporation) C:\Windows\system32\NetMgmtIF.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000509408 _____ (Microsoft Corporation) C:\Windows\system32\vmsynthstor.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000458752 _____ (Microsoft Corporation) C:\Windows\system32\vmvpci.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000439792 _____ (Microsoft Corporation) C:\Windows\system32\vmprox.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000439792 _____ (Microsoft Corporation) C:\Windows\system32\nvspinfo.exe
2024-07-15 16:41 - 2024-06-12 12:35 - 000435680 _____ (Microsoft Corporation) C:\Windows\system32\vmsmb.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000407024 _____ (Microsoft Corporation) C:\Windows\system32\vmdynmem.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000406912 _____ (Microsoft Corporation) C:\Windows\system32\nmscrub.exe
2024-07-15 16:41 - 2024-06-12 12:35 - 000398832 _____ (Microsoft Corporation) C:\Windows\system32\VmSynthNic.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000378336 _____ (Microsoft Corporation) C:\Windows\system32\vmflexio.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000366048 _____ (Microsoft Corporation) C:\Windows\system32\vmiccore.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000366048 _____ (Microsoft Corporation) C:\Windows\system32\hcsdiag.exe
2024-07-15 16:41 - 2024-06-12 12:35 - 000361952 _____ (Microsoft Corporation) C:\Windows\system32\gpupvdev.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000341472 _____ (Microsoft Corporation) C:\Windows\system32\WindowsSandboxClient.exe
2024-07-15 16:41 - 2024-06-12 12:35 - 000329184 _____ (Microsoft Corporation) C:\Windows\system32\vp9fs.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000316800 _____ (Microsoft Corporation) C:\Windows\system32\VmCrashDump.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000275936 _____ (Microsoft Corporation) C:\Windows\system32\CExecSvc.exe
2024-07-15 16:41 - 2024-06-12 12:35 - 000271840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storvsp.sys
2024-07-15 16:41 - 2024-06-12 12:35 - 000258048 _____ (Microsoft Corporation) C:\Windows\system32\hnsdiag.exe
2024-07-15 16:41 - 2024-06-12 12:35 - 000255472 _____ (Microsoft Corporation) C:\Windows\system32\vmbusvdev.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000243056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcivsp.sys
2024-07-15 16:41 - 2024-06-12 12:35 - 000226672 _____ C:\Windows\system32\IsolatedWindowsEnvironmentUtils.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000222704 _____ (Microsoft Corporation) C:\Windows\system32\vmickrnl.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000218608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fse.sys
2024-07-15 16:41 - 2024-06-12 12:35 - 000185712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbkmclr.sys
2024-07-15 16:41 - 2024-06-12 12:35 - 000169344 _____ (Microsoft Corporation) C:\Windows\system32\vmvirtio.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000131072 _____ C:\Windows\system32\hvsiproxyapp.exe
2024-07-15 16:41 - 2024-06-12 12:35 - 000128384 _____ (Microsoft Corporation) C:\Windows\system32\nmbind.exe
2024-07-15 16:41 - 2024-06-12 12:35 - 000120176 _____ (Microsoft Corporation) C:\Windows\system32\vmwpctrl.dll
2024-07-15 16:41 - 2024-06-12 12:35 - 000087520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdparser.sys
2024-07-15 16:41 - 2024-05-15 17:06 - 000140672 _____ (Microsoft Corporation) C:\Windows\system32\madrid.dll
2024-07-15 16:41 - 2024-05-15 17:06 - 000139264 _____ (Microsoft Corporation) C:\Windows\system32\CCG.exe
2024-07-15 16:41 - 2024-05-15 17:06 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\vmhbmgmt.dll
2024-07-15 16:41 - 2024-05-15 17:06 - 000124384 _____ (Microsoft Corporation) C:\Windows\system32\CmAgent.dll
2024-07-15 16:41 - 2024-05-15 17:06 - 000116080 _____ (Microsoft Corporation) C:\Windows\system32\wcsetupagent.exe
2024-07-15 16:41 - 2024-05-15 17:06 - 000081920 _____ (Microsoft Corporation) C:\Windows\system32\CCGLaunchPad.dll
2024-07-15 16:41 - 2024-05-15 17:06 - 000075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\VmsProxyHNic.sys
2024-07-15 16:41 - 2024-05-15 17:06 - 000071136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\VmsProxy.sys
2024-07-15 16:41 - 2024-05-15 17:06 - 000066944 _____ (Microsoft Corporation) C:\Windows\system32\NvAgent.dll
2024-07-15 16:41 - 2023-12-04 03:23 - 000094208 _____ C:\Windows\system32\Drivers\vmbusproxy.sys
2024-07-15 16:41 - 2023-12-04 03:23 - 000087520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\l2bridge.sys
2024-07-15 16:41 - 2023-12-04 03:23 - 000079344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vkrnlintvsc.sys
2024-07-15 16:41 - 2023-12-04 03:23 - 000079328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vkrnlintvsp.sys
2024-07-15 16:41 - 2023-12-04 03:23 - 000066928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvsocketcontrol.sys
2024-07-15 16:41 - 2023-12-04 03:23 - 000050656 _____ (Microsoft Corporation) C:\Windows\system32\VrdUmed.dll
2024-07-15 16:41 - 2023-12-04 03:23 - 000046552 _____ (Microsoft Corporation) C:\Windows\system32\vmsifproxystub.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000144736 _____ (Microsoft Corporation) C:\Windows\system32\rdp4vs.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000132456 _____ C:\Windows\system32\secfw_AuthenticAMD.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000124240 _____ (Microsoft Corporation) C:\Windows\system32\vmwpevents.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000095584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pvhdparser.sys
2024-07-15 16:41 - 2022-05-07 02:20 - 000075104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\passthruparser.sys
2024-07-15 16:41 - 2022-05-07 02:20 - 000058704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hnswfpdriver.sys
2024-07-15 16:41 - 2022-05-07 02:20 - 000054608 _____ (Microsoft Corporation) C:\Windows\system32\UtilityVmSysprep.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000042344 _____ (Microsoft Corporation) C:\Windows\system32\vmcomputeeventlog.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\VmComputeProxy.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000025960 _____ (Microsoft Corporation) C:\Windows\system32\f989b52d-f928-44a3-9bf1-bf0c1da6a0d6_HyperV-DeviceVirtualization.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000025960 _____ (Microsoft Corporation) C:\Windows\system32\07409496-a423-4a3e-b620-2cfb01a9318d_HyperV-ComputeNetwork.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000025952 _____ (Microsoft Corporation) C:\Windows\system32\f1db7d81-95be-4911-935a-8ab71629112a_HyperV-IsolatedVM.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000025952 _____ (Microsoft Corporation) C:\Windows\system32\d4d78066-e6db-44b7-b5cd-2eb82dce620c_HyperV-ComputeLegacy.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000025952 _____ (Microsoft Corporation) C:\Windows\system32\c4d66f00-b6f0-4439-ac9b-c5ea13fe54d7_HyperV-ComputeCore.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000025952 _____ (Microsoft Corporation) C:\Windows\system32\c28c7a4e-a619-4463-82b7-0fc9cc7187f5_HyperV-ComputeStorage.dll
2024-07-15 16:41 - 2022-05-07 02:20 - 000006658 _____ C:\Windows\system32\VmFirmwareHcl Third-Party Notices.txt
2024-07-15 16:41 - 2022-05-07 02:20 - 000006658 _____ C:\Windows\system32\VmFirmware Third-Party Notices.txt
2024-07-14 15:40 - 2024-03-23 19:09 - 000000000 ____D C:\Users\Net\AppData\Roaming\Zoom
2024-07-13 13:17 - 2024-03-06 21:38 - 000003629 _____ C:\Users\Net\Desktop\Novo(a) Documento de Texto.txt
2024-07-13 11:16 - 2024-03-24 18:53 - 000000000 ____D C:\Users\Net\AppData\Local\Learnpulse
2024-07-13 11:16 - 2024-03-24 18:52 - 000000000 ____D C:\Users\Net\AppData\Roaming\Learnpulse
2024-07-10 20:55 - 2024-03-05 17:00 - 000000000 ____D C:\ProgramData\Packages
2024-07-10 18:00 - 2023-12-04 03:29 - 000000000 ____D C:\Windows\system32\Microsoft-Edge-WebView
2024-07-10 18:00 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\UUS
2024-07-10 18:00 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2024-07-10 18:00 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\SystemResources
2024-07-10 18:00 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\system32\WinMetadata
2024-07-10 18:00 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\system32\Sgrm
2024-07-10 18:00 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2024-07-10 18:00 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\system32\oobe
2024-07-10 17:59 - 2022-05-07 07:41 - 000000000 ____D C:\Windows\InboxApps
2024-07-10 17:59 - 2022-05-07 02:24 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-07-10 17:59 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\ShellExperiences
2024-07-10 17:59 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\ShellComponents
2024-07-10 17:59 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\Provisioning
2024-07-10 17:59 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\PolicyDefinitions
2024-07-10 17:59 - 2022-05-07 02:24 - 000000000 ____D C:\Windows\bcastdvr
2024-07-10 17:19 - 2024-04-10 22:14 - 000000000 ____D C:\Windows\system32\MRT
2024-07-10 17:16 - 2024-04-10 22:14 - 194135240 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2024-07-10 17:08 - 2024-03-05 19:58 - 003212800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-07-09 10:18 - 2024-03-09 14:18 - 000004321 _____ C:\Users\Net\Desktop\Novo(a) Documento de Texto (2).txt
2024-07-08 18:27 - 2024-03-06 04:47 - 000000000 ____D C:\Users\Net\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WPS Office
2024-07-06 03:07 - 2024-06-15 16:16 - 000001104 _____ C:\Users\Public\Desktop\TubeDigger.lnk
2024-07-06 03:07 - 2024-06-15 16:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TubeDigger
2024-07-06 03:07 - 2024-06-15 16:16 - 000000000 ____D C:\Program Files (x86)\TubeDigger
2024-07-03 11:06 - 2024-06-15 15:28 - 000000000 ____D C:\ProgramData\IObit
2024-07-02 18:28 - 2024-05-15 20:58 - 000000000 ____D C:\Users\Net\AppData\Roaming\LosslessCut

==================== Arquivos na raiz de alguns diretórios ========

2024-06-01 06:03 - 2024-06-01 06:03 - 003364512 _____ (Nicolas Coolman) C:\Users\Neo\ZHPCleaner.exe
2024-04-29 16:53 - 2024-04-29 16:53 - 000000171 _____ () C:\Users\Neo\AppData\Roaming\822f02e4-9e9a-4077-a765-71edfca16ad0
2024-04-26 17:54 - 2024-05-13 19:50 - 000007859 _____ () C:\Users\Neo\AppData\Roaming\pcouffin.cat
2024-04-26 17:54 - 2024-05-13 19:50 - 000001167 _____ () C:\Users\Neo\AppData\Roaming\pcouffin.inf
2024-04-26 17:54 - 2024-05-13 19:50 - 000000034 _____ () C:\Users\Neo\AppData\Roaming\pcouffin.log
2024-05-13 19:50 - 2024-05-13 19:50 - 000082816 _____ (VSO Software) C:\Users\Neo\AppData\Roaming\pcouffin.sys

==================== SigCheck ============================

(Não há correção automática para arquivos que não passaram na verificação.)

==================== Fim de FRST.txt ========================





Resultado da análise adicional Farbar Recovery Scan Tool (x64) Versão: 28.07.2024
Executado por Neo (30-07-2024 17:35:17)
Executando a partir de C:\Users\Net\Desktop
Microsoft Windows 11 Pro Versão 23H2 22631.3880 (X64) (2024-03-05 20:00:10)
Modo da Inicialização: Normal
==========================================================


==================== Contas: =============================


(Se uma entrada for incluída na fixlist, será removida.)

Administrador (S-1-5-21-1875411646-3612572813-2532316385-500 - Administrator - Disabled)
Convidado (S-1-5-21-1875411646-3612572813-2532316385-501 - Limited - Disabled)
DefaultAccount (S-1-5-21-1875411646-3612572813-2532316385-503 - Limited - Disabled)
Neo (S-1-5-21-1875411646-3612572813-2532316385-1001 - Administrator - Enabled) => C:\Users\Neo
Net (S-1-5-21-1875411646-3612572813-2532316385-1002 - Limited - Enabled) => C:\Users\Net
WDAGUtilityAccount (S-1-5-21-1875411646-3612572813-2532316385-504 - Limited - Disabled)

==================== Central de Segurança ========================

(Se uma entrada for incluída na fixlist, será removida.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas Instalados ======================

(Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.)

7-Zip 24.01 (x64) (HKLM\...\7-Zip) (Version: 24.01 - Igor Pavlov)
Boilsoft Video Splitter 8.3.3 (HKU\S-1-5-21-1875411646-3612572813-2532316385-1002\...\cfc26c2a-150b-5ef7-9bdf-a41433ec180c) (Version: 8.3.3 - )
CapCut (HKU\S-1-5-21-1875411646-3612572813-2532316385-1001\...\CapCut) (Version: 3.8.0.1431 - Bytedance Pte. Ltd.)
CrystalDiskInfo 9.2.3 (HKLM\...\CrystalDiskInfo_is1) (Version: 9.2.3 - Crystal Dew World)
Doomsday 2.3.1.3685 (HKLM\...\{9D9190C1-135F-4107-A36F-09AE5EA318BE}) (Version: 2.3.1.3685 - dengine.net)
FastStone Image Viewer 7.8 (HKLM-x32\...\FastStone Image Viewer) (Version: 7.8 - FastStone Corporation)
FormatFactory 5.17.0.0 (HKLM-x32\...\FormatFactory) (Version: 5.17.0.0 - Free Time)
Foxit PDF Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 2024.2.2.25170 - Foxit Software Inc.)
FreeCAD 0.21.2 (Instalado para o Usuário Atual) (HKU\S-1-5-21-1875411646-3612572813-2532316385-1002\...\FreeCAD0212) (Version: 0.21.2 - FreeCAD Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 127.0.6533.73 - Google LLC)
HandBrake 1.8.1 (HKLM-x32\...\HandBrake) (Version: 1.8.1 - )
HP DeskJet 2130 series Software básico do dispositivo (HKLM\...\{30135B68-7334-4D1B-8AB4-A79EF84ECDE1}) (Version: 40.15.1230.21319 - HP Inc.)
HP Dropbox Plugin (HKLM-x32\...\{8533E879-3794-426D-96B1-B010B56B03F5}) (Version: 40.13.54.81239 - HP)
HP Google Drive Plugin (HKLM-x32\...\{57E78C1A-6BCB-42E9-B3A5-54A05CA85E1C}) (Version: 40.13.54.81239 - HP)
K-Lite Mega Codec Pack 18.2.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 18.2.0 - KLCP)
Microsoft .NET Host - 6.0.27 (x64) (HKLM\...\{3A96B93E-763F-41E7-85C7-1F3CCC37EF27}) (Version: 48.108.8828 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.5 (x64) (HKLM\...\{8FB40332-CD49-4E77-A40D-E2D09368632D}) (Version: 64.20.13583 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.27 (x64) (HKLM\...\{7447A794-FA2E-42BE-BA9A-5FCBD54C5DF3}) (Version: 48.108.8828 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.5 (x64) (HKLM\...\{25F6351D-21A3-4E92-964E-01E864A21AB1}) (Version: 64.20.13583 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.27 (x64) (HKLM\...\{79043ED0-7ED1-4227-A5E5-04C5594D21F7}) (Version: 48.108.8828 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.5 (x64) (HKLM\...\{26037618-FB6D-47BC-9F99-4C4323C4CEC6}) (Version: 64.20.13583 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 127.0.2651.74 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 126.0.2592.113 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1875411646-3612572813-2532316385-1002\...\OneDriveSetup.exe) (Version: 24.132.0701.0002 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33810 (HKLM-x32\...\{5af95fd8-a22e-458f-acee-c61bd787178e}) (Version: 14.40.33810.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.40.33810 (HKLM\...\{59CED48F-EBFE-480C-8A38-FC079C2BEC0F}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.40.33810 (HKLM\...\{B8B3BB4A-A10D-4F51-91B7-A64FFAC31EA7}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.27 (x64) (HKLM\...\{E634F316-BEB6-4FB3-A612-F7102F576165}) (Version: 48.108.8836 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.27 (x64) (HKLM-x32\...\{d87ae0f4-64a6-4b94-859a-530b9c313c27}) (Version: 6.0.27.33320 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.5 (x64) (HKLM\...\{CE4D0B17-4E11-41F9-8C3B-73F61DFE0797}) (Version: 64.20.13589 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.5 (x64) (HKLM-x32\...\{f1becfe0-3a94-4d8f-ba39-c5853803edda}) (Version: 8.0.5.33617 - Microsoft Corporation)
MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox (x64 pt-BR) (HKLM\...\Mozilla Firefox 128.0.3 (x64 pt-BR)) (Version: 128.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 115.8.1 - Mozilla)
Mozilla Thunderbird (x64 pt-BR) (HKLM\...\Mozilla Thunderbird 115.13.0 (x64 pt-BR)) (Version: 115.13.0 - Mozilla)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 30.2.2 - OBS Project)
Oracle VM VirtualBox 7.0.18 (HKLM\...\{7431991E-0534-4E1E-89C8-2AF6968C017C}) (Version: 7.0.18 - Oracle and/or its affiliates)
PaperScan 3 Free Edition (HKLM-x32\...\{87B0142A-373A-4A08-90E8-A75C2027808E}) (Version: 3.0.130 - ORPALIS)
qBittorrent (HKLM-x32\...\qBittorrent) (Version: 4.6.5 - The qBittorrent project)
Telegram Desktop (HKU\S-1-5-21-1875411646-3612572813-2532316385-1002\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 5.2.3 - Telegram FZ-LLC)
TubeDigger 7.7.3 (HKLM-x32\...\{1E3745C1-674D-4B2E-B8F7-3F4088950ED7}_is1) (Version: 7.7.3 - TubeDigger)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.14.0 - Tweaking.com)
WonderFox DVD Ripper Pro 23.0 (HKLM-x32\...\WonderFox DVD Ripper Pro) (Version: 23.0 - WonderFox Soft, Inc.)
WPS Office (12.2.0.17153) (HKU\S-1-5-21-1875411646-3612572813-2532316385-1002\...\Kingsoft Office) (Version: 12.2.0.17153 - Kingsoft Corp.)
Zoom (HKU\S-1-5-21-1875411646-3612572813-2532316385-1002\...\ZoomUMX) (Version: 5.17.11 (34827) - Zoom Video Communications, Inc.)

Packages:
=========

Fotos -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2024.11070.19012.0_x64__8wekyb3d8bbwe [2024-07-25] (Microsoft Corporation) [Startup Task]
Windows Feature Experience Pack -> C:\Windows\SystemApps\MicrosoftWindows.Client.LKG_cw5n1h2txyewy [2024-07-10] (Microsoft Windows)

==================== Análise Personalizada CLSID (Whitelisted): ==============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileCoAuth.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{07CA83F0-DF06-4E67-89DD-E80924A49512}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileCoAuth.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{0827D883-485C-4D62-BA2C-A332DBF3D4B0}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileCoAuth.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{20894375-46AE-46E2-BAFD-CB38975CDCE6}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{2e7c0a19-0438-41e9-81e3-3ad3d64f55ba}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /cci /client=Personal => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileCoAuth.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{3A308EFE-656D-46BB-9963-0A41C0D6BCA2}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileCoAuth.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\Microsoft.SharePoint.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{5999E1EE-711E-48D2-9884-851A709F543D}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /autoplay => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{6bb93b4e-44d8-40e2-bd97-42dbcf18a40f}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /cci => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileCoAuth.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /cci /client=Personal => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\Microsoft.SharePoint.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileCoAuth.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileCoAuth.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{9AA2F32D-362A-42D9-9328-24A483E2CCC3}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{A3CA1CF4-5F3E-4AC0-91B9-0D3716E1EAC3}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /cci /client=Personal => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileCoAuth.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /cci /client=Personal => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1001_Classes\CLSID\{F37369D9-1C22-40A0-A997-0B4D5F7B6637}\localserver32 -> "C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileCoAuth.exe" => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1002_Classes\CLSID\{1a46400f-4c81-802a-c2c1-1e9a687a9340}\localserver32 -> C:\Program Files\HandBrake\HandBrake.exe (HandBrake Team) [Arquivo não assinado]
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1002_Classes\CLSID\{28A80003-18FD-411D-B0A3-3C81F618E22B}\InprocServer32 -> C:\Users\Net\AppData\Local\Kingsoft\WPS Office\12.2.0.17153\office6\kwpsmenushellext64.dll (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1002_Classes\CLSID\{38cf1c8d-6ef4-5049-e979-72309843229c}\localserver32 -> "C:\Users\Net\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe" -ToastActivated => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-1875411646-3612572813-2532316385-1002_Classes\CLSID\{48ce1c96-b3fb-4ec5-9c32-55cb22a77544}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll => Nenhum Arquivo
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ContextMenuHandlers1: [1XdShellExt] -> {B4E15CD0-F916-4C8E-830A-15E3E9D01A1B} => C:\Users\Neo\AppData\Roaming\SwifDooPDFData\PDFShell64.dll -> Nenhum Arquivo
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-01-31] (Igor Pavlov) [Arquivo não assinado]
ContextMenuHandlers1: [FormatFactoryShell] -> {A3888923-CFD3-4A6B-89BF-08E6B95716E8} => C:\Program Files (x86)\FormatFactory\ShellEx_108.dll [2024-01-04] (Free Time) [Arquivo não assinado]
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-01-31] (Igor Pavlov) [Arquivo não assinado]
ContextMenuHandlers4: [FormatFactoryShell] -> {A3888923-CFD3-4A6B-89BF-08E6B95716E8} => C:\Program Files (x86)\FormatFactory\ShellEx_108.dll [2024-01-04] (Free Time) [Arquivo não assinado]
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-01-31] (Igor Pavlov) [Arquivo não assinado]
ContextMenuHandlers1_S-1-5-21-1875411646-3612572813-2532316385-1001: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ContextMenuHandlers4_S-1-5-21-1875411646-3612572813-2532316385-1001: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ContextMenuHandlers5_S-1-5-21-1875411646-3612572813-2532316385-1001: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ContextMenuHandlers1_S-1-5-21-1875411646-3612572813-2532316385-1002: [          kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} =>  -> Nenhum Arquivo
ContextMenuHandlers1_S-1-5-21-1875411646-3612572813-2532316385-1002: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ContextMenuHandlers2_S-1-5-21-1875411646-3612572813-2532316385-1002: [AgentRansack] -> {2AE9D6D8-E348-4853-B266-C78844D31B97} =>  -> Nenhum Arquivo
ContextMenuHandlers4_S-1-5-21-1875411646-3612572813-2532316385-1002: [          kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} =>  -> Nenhum Arquivo
ContextMenuHandlers4_S-1-5-21-1875411646-3612572813-2532316385-1002: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ContextMenuHandlers4_S-1-5-21-1875411646-3612572813-2532316385-1002: [AgentRansack] -> {2AE9D6D8-E348-4853-B266-C78844D31B97} =>  -> Nenhum Arquivo
ContextMenuHandlers5_S-1-5-21-1875411646-3612572813-2532316385-1002: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Users\Neo\AppData\Local\Microsoft\OneDrive\24.025.0204.0003\FileSyncShell64.dll -> Nenhum Arquivo
ContextMenuHandlers5_S-1-5-21-1875411646-3612572813-2532316385-1002: [AgentRansack] -> {2AE9D6D8-E348-4853-B266-C78844D31B97} =>  -> Nenhum Arquivo
ContextMenuHandlers6_S-1-5-21-1875411646-3612572813-2532316385-1002: [AgentRansack] -> {2AE9D6D8-E348-4853-B266-C78844D31B97} =>  -> Nenhum Arquivo

==================== Codecs (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\system32\x264vfw64.dll [3799552 2017-07-30] (x264vfw project) [Arquivo não assinado]
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\system32\lagarith.dll [148992 2011-12-07] () [Arquivo não assinado]
HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\system32\xvidvfw.dll [310784 2019-12-28] () [Arquivo não assinado]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\system32\ac3acm.acm [180736 2012-07-21] (fccHandler) [Arquivo não assinado]
HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\SysWOW64\x264vfw.dll [3850240 2017-07-30] (x264vfw project) [Arquivo não assinado]
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-07] () [Arquivo não assinado]
HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [284160 2019-12-28] () [Arquivo não assinado]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\ac3acm.acm [122880 2012-07-21] (fccHandler) [Arquivo não assinado]

==================== Atalhos & WMI ========================

==================== Módulos Carregados (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Modo de Segurança (Whitelisted) ==================

(Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"

==================== Associação (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

BHO: Sem Nome -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> Nenhum Arquivo

==================== Hosts Conteúdo: =========================

(Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.)

2022-05-07 02:24 - 2024-03-22 09:51 - 000000855 _____ C:\Windows\system32\drivers\etc\hosts
127.0.0.1      localhost

2024-07-15 21:03 - 2024-07-17 18:28 - 000000617 _____ C:\Windows\system32\drivers\etc\hosts.ics
172.29.157.217 22922b9a-4629-4236-b491-5ac7cafb2365.mshome.net # 2024 7 3 24 21 28 39 457
172.29.92.225 4e65c691-6d8c-4623-991c-1b7fb7b055ba.mshome.net # 2024 7 2 23 0 25 57 481
172.29.144.1 Matrix2025.mshome.net # 2029 7 1 16 21 28 39 457

==================== Outras Áreas ===========================

(Atualmente não há nenhuma correção automática para esta seção.)

HKU\S-1-5-21-1875411646-3612572813-2532316385-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-1875411646-3612572813-2532316385-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img19.jpg
DNS Servers: 181.213.132.6 - 181.213.132.7
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Firewall do Windows está habilitado.

Network Binding:
=============

vms_vsf: Filtro de Extensão de Comutador Virtual Hyper-V
oracle_VBoxNetLwf: VirtualBox NDIS6 Bridged Networking Driver
ms_winvfp: Microsoft Azure VFP Switch Filter Extension
vms_vsp: Hyper-V Virtual Switch Extension Protocol

==================== MSCONFIG/TASK MANAGER ítens desabilitados ==

(Se uma entrada for incluída na fixlist, será removida.)

HKU\S-1-5-21-1875411646-3612572813-2532316385-1002\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1875411646-3612572813-2532316385-1002\...\StartupApproved\Run: => "Privacy Eraser"
HKU\S-1-5-21-1875411646-3612572813-2532316385-1002\...\StartupApproved\Run: => "CCleaner Smart Cleaning"

==================== Regras do Firewall (Whitelisted) ================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

FirewallRules: [{977D5438-2C8B-4637-A121-A395C0D1C647}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{A37DE8A9-647F-49F1-8947-B7B91E437198}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{4C5224C8-301E-4FA6-B33C-776CE35E6CD3}] => (Allow) C:\Users\Net\AppData\Local\Kingsoft\WPS Office\12.2.0.13489\office6\wps.exe => Nenhum Arquivo
FirewallRules: [{D01E8303-88E3-4372-87C8-241251717654}] => (Allow) C:\Users\Net\AppData\Local\Kingsoft\WPS Office\12.2.0.13489\office6\wpscloudsvr.exe => Nenhum Arquivo
FirewallRules: [{80EC98A6-E96F-49D3-BC7F-628E238B6BA9}] => (Allow) C:\Users\Net\AppData\Local\Kingsoft\WPS Office\12.2.0.13489\office6\promecefpluginhost.exe => Nenhum Arquivo
FirewallRules: [{96309AED-7551-48E5-B069-3C4D18957D7A}] => (Allow) C:\Users\Neo\AppData\Local\Temp\7zS22B1\HP.EasyStart.exe => Nenhum Arquivo
FirewallRules: [{6F7B5A15-0D45-498F-978D-A84D5EB8F133}] => (Allow) C:\Users\Neo\AppData\Local\Temp\7zS4EAB\HP.EasyStart.exe => Nenhum Arquivo
FirewallRules: [{B3F026C0-2C49-4896-A79A-F88CE227577C}] => (Allow) C:\Users\Neo\AppData\Local\Temp\7zS21AA\HP.EasyStart.exe => Nenhum Arquivo
FirewallRules: [{B5D2C557-0FA1-463F-9783-E50F1C497B83}] => (Allow) C:\Program Files\HP\HP DeskJet 2130 series\Bin\USBSetup.exe (HP Inc. -> HP Inc.)
FirewallRules: [{D9E7E3C4-EDEB-4A4F-AE64-34BD2A2EC699}] => (Allow) C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPNetworkCommunicatorCom.exe (HP Inc. -> HP Inc.)
FirewallRules: [{71AD41E4-9C71-40CA-91A3-9E096FC27ACC}] => (Allow) C:\Program Files (x86)\FormatFactory\FormatFactory.exe (Free Time Software Technology Co., Ltd. -> Free Time Co., Ltd.)
FirewallRules: [TCP Query User{F37BC3C0-3712-4A1A-8C74-04A3006AAAD5}E:\matrix\downloads\dreamule_bin\emule.exe] => (Allow) E:\matrix\downloads\dreamule_bin\emule.exe => Nenhum Arquivo
FirewallRules: [UDP Query User{EFB9946B-19EC-43AC-B6E0-EBEDA07CC6F2}E:\matrix\downloads\dreamule_bin\emule.exe] => (Allow) E:\matrix\downloads\dreamule_bin\emule.exe => Nenhum Arquivo
FirewallRules: [TCP Query User{C821544E-EF83-4684-B5BD-509D11799F6A}C:\program files (x86)\emule\emule.exe] => (Allow) C:\program files (x86)\emule\emule.exe => Nenhum Arquivo
FirewallRules: [UDP Query User{AB9C677C-0D2C-411E-97BA-4E68C73A9D49}C:\program files (x86)\emule\emule.exe] => (Allow) C:\program files (x86)\emule\emule.exe => Nenhum Arquivo
FirewallRules: [TCP Query User{0A4B9458-169C-43FB-A5F8-84DD0E95310E}C:\program files (x86)\ares\ares.exe] => (Allow) C:\program files (x86)\ares\ares.exe => Nenhum Arquivo
FirewallRules: [UDP Query User{6E4748F4-DFC2-476E-BB4D-5D1A1FF94615}C:\program files (x86)\ares\ares.exe] => (Allow) C:\program files (x86)\ares\ares.exe => Nenhum Arquivo
FirewallRules: [{7EE1DA7C-FA9A-4DEF-A319-51995581E830}] => (Allow) C:\Users\Net\Downloads\hitpaw-edimakor.exe => Nenhum Arquivo
FirewallRules: [{87FB275E-34B6-4288-B4D9-BCABCCA6A10B}] => (Allow) C:\Users\Net\Downloads\hitpaw-edimakor.exe => Nenhum Arquivo
FirewallRules: [{D03073F4-7644-49B9-9D67-B9781FBF580B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => Nenhum Arquivo
FirewallRules: [{28000B34-7BF2-474D-9D5D-A15578AE25B1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => Nenhum Arquivo
FirewallRules: [{F2F668F5-7DD7-4809-8282-B637488776F7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => Nenhum Arquivo
FirewallRules: [{0648CB0F-B5CC-4C12-A3F0-3581F5704FF3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => Nenhum Arquivo
FirewallRules: [{B2860D58-2015-49D3-8683-993CD30B91C8}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_21253.510.996.1465_x64__8wekyb3d8bbwe\msteams.exe => Nenhum Arquivo
FirewallRules: [{17EFE77D-9BB4-4BE7-A785-BE5AADA9B675}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_21253.510.996.1465_x64__8wekyb3d8bbwe\msteams.exe => Nenhum Arquivo
FirewallRules: [{418004B6-A1B8-4BD6-812F-AF56ADA12443}] => (Allow) C:\Program Files (x86)\FormatFactory\FormatFactory.exe (Free Time Software Technology Co., Ltd. -> Free Time Co., Ltd.)
FirewallRules: [TCP Query User{718890CA-676B-4D11-AF6A-17F497CFBF27}C:\users\net\appdata\local\zoom\plugin\webview2_x64\120.0.2210.91\msedgewebview2.exe] => (Allow) C:\users\net\appdata\local\zoom\plugin\webview2_x64\120.0.2210.91\msedgewebview2.exe => Nenhum Arquivo
FirewallRules: [UDP Query User{8BFDD4AD-8C47-4894-8793-C41817E9504E}C:\users\net\appdata\local\zoom\plugin\webview2_x64\120.0.2210.91\msedgewebview2.exe] => (Allow) C:\users\net\appdata\local\zoom\plugin\webview2_x64\120.0.2210.91\msedgewebview2.exe => Nenhum Arquivo
FirewallRules: [TCP Query User{186DFB0E-CE93-442A-924A-4110B9337F00}C:\users\net\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\net\appdata\roaming\zoom\bin\zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [UDP Query User{E1AC5219-8CE5-457A-89CA-09D90B09B910}C:\users\net\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\net\appdata\roaming\zoom\bin\zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{DEE256AD-D7C4-4F58-B23A-F31F8ECECDB6}] => (Allow) C:\Users\Net\Downloads\hitpaw-video-converter.exe => Nenhum Arquivo
FirewallRules: [{51D447A4-B562-485F-986F-05FC5FEDF811}] => (Allow) C:\Users\Net\Downloads\hitpaw-video-converter.exe => Nenhum Arquivo
FirewallRules: [TCP Query User{1E34A6F4-8ADA-4663-A2E0-3F967AD12F5F}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{EAF01C9F-81E2-4C0E-BB45-086C88A589C7}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{30D54B27-EE9C-4351-A460-E9EAE1D38D16}] => (Allow) C:\Program Files (x86)\FormatFactory\FormatFactory.exe (Free Time Software Technology Co., Ltd. -> Free Time Co., Ltd.)
FirewallRules: [TCP Query User{011BA5E7-0B59-48C2-BC74-FFC4F7F65DA1}C:\program files\doomsday 2.3.1\bin\doomsday.exe] => (Allow) C:\program files\doomsday 2.3.1\bin\doomsday.exe () [Arquivo não assinado]
FirewallRules: [UDP Query User{A781F7C6-87AE-4E1E-89A2-911AF3224FFD}C:\program files\doomsday 2.3.1\bin\doomsday.exe] => (Allow) C:\program files\doomsday 2.3.1\bin\doomsday.exe () [Arquivo não assinado]
FirewallRules: [{4F985333-73FC-48DF-94CD-5623148D6696}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [Arquivo não assinado]
FirewallRules: [{75EEF45F-12A8-499F-94C3-C22B02A2DA8E}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [Arquivo não assinado]
FirewallRules: [{9A6045A9-BC80-469A-A07C-A4DF9BEF7993}] => (Allow) C:\Program Files (x86)\TubeDigger\TubeDigger.exe (TubeDigger) [Arquivo não assinado]
FirewallRules: [{4B857984-6B81-47FB-BFE8-425BF5A31669}] => (Allow) C:\Program Files (x86)\TubeDigger\CEF3\TubeDgr3.exe (TubeDigger) [Arquivo não assinado]
FirewallRules: [{F663F982-C061-4325-AD1B-B095021BF07C}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.113\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4ECE18A9-939E-4F92-8FA5-04F771E43EAE}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Pontos de Restauração =========================

30-07-2024 16:34:27 ZHPcleaner

==================== Dispositivos Apresentando Falhas No Gerenciador ============


==================== Erros no Log de eventos: ========================

Erros em Aplicativos:
==================
Error: (07/30/2024 12:26:14 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Erro do Serviço de Cópias de Sombra de Volume: erro inesperado ao consultar a interface IVssWriterCallback.  hr =  0x80070005, Acesso negado..Muitas vezes, isso é causado por configurações de segurança incorretas no processo gravador ou solicitante.


Operação:
  Obtendo Dados do Gravador

Contexto:
  Id de Classe de Gravador: {e8132975-6f93-4464-a53e-1050253ae220}
  Nome do Gravador: System Writer
  ID de Instância de Gravador: {52da0391-c87d-48b3-89f0-05e9b261f172}

Error: (07/30/2024 05:31:06 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Falha na geração de contexto de ativação para "C:\Users\Neo\AppData\Local\CapCut\Apps\CapCut.exe". Erro no arquivo de manifesto ou de política "", na linha .
Uma versão de componente exigida pelo aplicativo está em conflito com outra versão de componente já ativa.
Os componentes conflitantes são:
Componente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.3672_none_6ec0f0a887fe525b.manifest.
Componente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.3672_none_2713b9d173822955.manifest.

Error: (07/28/2024 07:34:27 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Erro do Serviço de Cópias de Sombra de Volume: erro inesperado ao consultar a interface IVssWriterCallback.  hr =  0x80070005, Acesso negado..Muitas vezes, isso é causado por configurações de segurança incorretas no processo gravador ou solicitante.


Operação:
  Obtendo Dados do Gravador

Contexto:
  Id de Classe de Gravador: {e8132975-6f93-4464-a53e-1050253ae220}
  Nome do Gravador: System Writer
  ID de Instância de Gravador: {7d2217c2-4784-409a-a1c2-294abdcadd2f}

Error: (07/28/2024 03:43:29 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Erro do Serviço de Cópias de Sombra de Volume: erro inesperado ao consultar a interface IVssWriterCallback.  hr =  0x80070005, Acesso negado..Muitas vezes, isso é causado por configurações de segurança incorretas no processo gravador ou solicitante.


Operação:
  Obtendo Dados do Gravador

Contexto:
  Id de Classe de Gravador: {e8132975-6f93-4464-a53e-1050253ae220}
  Nome do Gravador: System Writer
  ID de Instância de Gravador: {9b057f36-23cf-45b6-b5e3-594f75951877}

Error: (07/27/2024 10:21:19 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Falha na geração de contexto de ativação para "C:\Program Files (x86)\SwifDooPDF\SwifDooHelper.exe". Erro no arquivo de manifesto ou de política "", na linha .
Uma versão de componente exigida pelo aplicativo está em conflito com outra versão de componente já ativa.
Os componentes conflitantes são:
Componente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.3672_none_6ec0f0a887fe525b.manifest.
Componente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.3672_none_2713b9d173822955.manifest.

Error: (07/27/2024 10:18:25 AM) (Source: Application Error) (EventID: 1000) (User: Matrix2025)
Description: Nome do aplicativo com falha: Explorer.EXE, versão: 10.0.22621.3880, carimbo de data/hora: 0x0a9e5890
Nome do módulo com falha: windows.storage.dll, versão: 10.0.22621.3880, carimbo de data/hora: 0x72b59cf0
Código de exceção: 0xc0000005
Deslocamento da falha: 0x000000000013a846
ID do processo com falha: 0x0x1b58
Hora de início do aplicativo com falha: 0x0x1dae025be3827f4
Caminho do aplicativo com falha: C:\Windows\Explorer.EXE
Caminho do módulo com falha: C:\Windows\SYSTEM32\windows.storage.dll
ID do Relatório: ec29888b-ac3f-463e-b659-d871d702017e
Nome completo do pacote com falha:
ID do aplicativo relativo ao pacote com falha:

Error: (07/26/2024 08:17:31 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: AUTORIDADE NT)
Description: O hive do usuário é carregado por outro processo (Bloqueio de Registro). Nome do processo: C:\Windows\System32\svchost.exe, PID: 7448, ProfSvc PID: 1944.

Error: (07/26/2024 08:17:31 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: AUTORIDADE NT)
Description: O hive do usuário é carregado por outro processo (Bloqueio de Registro). Nome do processo: C:\Windows\System32\svchost.exe, PID: 4068, ProfSvc PID: 1944.


Erros de Sistema:
=============
Error: (07/30/2024 05:37:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Não foi possível iniciar o serviço Browser devido ao seguinte erro:
O serviço não respondeu à requisição de início ou controle em tempo hábil.

Error: (07/30/2024 05:37:02 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Tempo limite esgotado (30000 milissegundos) ao aguardar a conexão do serviço Browser.

Error: (07/30/2024 05:22:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Não foi possível iniciar o serviço Browser devido ao seguinte erro:
O serviço não respondeu à requisição de início ou controle em tempo hábil.

Error: (07/30/2024 05:22:07 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Tempo limite esgotado (30000 milissegundos) ao aguardar a conexão do serviço Browser.

Error: (07/30/2024 05:09:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Não foi possível iniciar o serviço Microsoft Update Health Service devido ao seguinte erro:
O sistema não pode encontrar o arquivo especificado.

Error: (07/30/2024 05:09:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Não foi possível iniciar o serviço Browser devido ao seguinte erro:
O serviço não respondeu à requisição de início ou controle em tempo hábil.

Error: (07/30/2024 05:09:10 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Tempo limite esgotado (30000 milissegundos) ao aguardar a conexão do serviço Browser.

Error: (07/30/2024 08:07:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Não foi possível iniciar o serviço Browser devido ao seguinte erro:
O serviço não respondeu à requisição de início ou controle em tempo hábil.


Windows Defender:
================
Date: 2024-07-30 17:34:42
Description:
Microsoft Defender Antivírus detectou PUA (aplicativo potencialmente indesejado).
Para obter mais informações, veja a seguir:
https://go.microsoft.com/fwlink/?linkid=37020&name=PUADlManager:Win32/OfferCore&threatid=311999&enterprise=0
Nome: PUADlManager:Win32/OfferCore
Gravidade: Baixo
Categoria: Software Potencialmente Indesejado
Caminho: file:_C:\Users\Net\Downloads\DTLite1210-2155.exe
Origem da Detecção: Computador local
Tipo da Detecção: Concreto
Fonte da Detecção: Proteção em Tempo Real
Usuário: Matrix2025\Neo
Nome do Processo: C:\Users\Net\Desktop\FRST64.exe
Versão da Inteligência de Segurança: AV: 1.415.409.0, AS: 1.415.409.0, NIS: 1.415.409.0
Versão do Mecanismo: AM: 1.1.24060.5, NIS: 1.1.24060.5

Date: 2024-07-30 16:42:57
Description:
Microsoft Defender Antivírus detectou PUA (aplicativo potencialmente indesejado).
Para obter mais informações, veja a seguir:
https://go.microsoft.com/fwlink/?linkid=37020&name=PUADlManager:Win32/OfferCore&threatid=311999&enterprise=0
Nome: PUADlManager:Win32/OfferCore
Gravidade: Baixo
Categoria: Software Potencialmente Indesejado
Caminho: file:_C:\Users\Net\Downloads\DTLite1210-2155.exe
Origem da Detecção: Computador local
Tipo da Detecção: Concreto
Fonte da Detecção: Proteção em Tempo Real
Usuário: Matrix2025\Net
Nome do Processo: C:\Windows\explorer.exe
Versão da Inteligência de Segurança: AV: 1.415.396.0, AS: 1.415.396.0, NIS: 1.415.396.0
Versão do Mecanismo: AM: 1.1.24060.5, NIS: 1.1.24060.5

Date: 2024-07-30 16:42:30
Description:
Microsoft Defender Antivírus detectou PUA (aplicativo potencialmente indesejado).
Para obter mais informações, veja a seguir:
https://go.microsoft.com/fwlink/?linkid=37020&name=PUADlManager:Win32/OfferCore&threatid=311999&enterprise=0
Nome: PUADlManager:Win32/OfferCore
Gravidade: Baixo
Categoria: Software Potencialmente Indesejado
Caminho: file:_C:\Users\Net\Downloads\DTLite1210-2155.exe
Origem da Detecção: Computador local
Tipo da Detecção: Concreto
Fonte da Detecção: Proteção em Tempo Real
Usuário: Matrix2025\Net
Nome do Processo: C:\Windows\explorer.exe
Versão da Inteligência de Segurança: AV: 1.415.396.0, AS: 1.415.396.0, NIS: 1.415.396.0
Versão do Mecanismo: AM: 1.1.24060.5, NIS: 1.1.24060.5

Date: 2024-07-30 13:28:32
Description:
Microsoft Defender Antivírus detectou PUA (aplicativo potencialmente indesejado).
Para obter mais informações, veja a seguir:
https://go.microsoft.com/fwlink/?linkid=37020&name=PUADlManager:Win32/OfferCore&threatid=311999&enterprise=0
Nome: PUADlManager:Win32/OfferCore
Gravidade: Baixo
Categoria: Software Potencialmente Indesejado
Caminho: file:_C:\Users\Net\Downloads\DTLite1210-2155.exe
Origem da Detecção: Computador local
Tipo da Detecção: Concreto
Fonte da Detecção: Proteção em Tempo Real
Usuário: Matrix2025\Neo
Nome do Processo: C:\Users\Net\Desktop\ZHPCleaner.exe
Versão da Inteligência de Segurança: AV: 1.415.396.0, AS: 1.415.396.0, NIS: 1.415.396.0
Versão do Mecanismo: AM: 1.1.24060.5, NIS: 1.1.24060.5

Date: 2024-07-30 13:28:15
Description:
Microsoft Defender Antivírus detectou PUA (aplicativo potencialmente indesejado).
Para obter mais informações, veja a seguir:
https://go.microsoft.com/fwlink/?linkid=37020&name=PUADlManager:Win32/OfferCore&threatid=311999&enterprise=0
Nome: PUADlManager:Win32/OfferCore
Gravidade: Baixo
Categoria: Software Potencialmente Indesejado
Caminho: file:_C:\Users\Net\Downloads\DTLite1210-2155.exe
Origem da Detecção: Computador local
Tipo da Detecção: Concreto
Fonte da Detecção: Proteção em Tempo Real
Usuário: Matrix2025\Neo
Nome do Processo: C:\Users\Net\Desktop\ZHPCleaner.exe
Versão da Inteligência de Segurança: AV: 1.415.396.0, AS: 1.415.396.0, NIS: 1.415.396.0
Versão do Mecanismo: AM: 1.1.24060.5, NIS: 1.1.24060.5
Event[0]

Date: 2024-03-22 09:49:37
Description:
Microsoft Defender Antivírus encontrou um erro ao tentar atualizar a inteligência de segurança.
Nova Versão da Inteligência de Segurança:
Versão da Inteligência de Segurança anterior: 1.407.622.0
Fonte da Atualização: Servidor do Microsoft Update
Tipo da Inteligência de Segurança: Antivírus
Tipo da atualização: Completa
Usuário: AUTORIDADE NT\SISTEMA
Versão Atual do Mecanismo:
Versão Anterior do Mecanismo: 1.1.24020.9
Código de Erro: 0x8007043c
Descrição do Erro: Não é possível compartilhar este serviço no modo de segurança 

Date: 2024-03-22 09:39:22
Description:
O recurso de Proteção em Tempo Real do Microsoft Defender Antivírus encontrou um erro e falhou.
Recurso: Em Tempo de Acesso
Código do Erro: 0x8007043c
Descrição do erro: Não é possível compartilhar este serviço no modo de segurança
Motivo: A inteligência de segurança antimalware parou de funcionar por um motivo desconhecido. Em alguns casos, reiniciar o serviço pode resolver o problema.

Date: 2024-03-16 12:03:58
Description:
Microsoft Defender Antivírus encontrou um erro ao tentar atualizar a inteligência de segurança.
Nova Versão da Inteligência de Segurança:
Versão da Inteligência de Segurança anterior: 1.407.471.0
Fonte da Atualização: Servidor do Microsoft Update
Tipo da Inteligência de Segurança: Antivírus
Tipo da atualização: Completa
Usuário: AUTORIDADE NT\SISTEMA
Versão Atual do Mecanismo:
Versão Anterior do Mecanismo: 1.1.24020.9
Código de Erro: 0x8007043c
Descrição do Erro: Não é possível compartilhar este serviço no modo de segurança 

Date: 2024-03-16 11:53:42
Description:
O recurso de Proteção em Tempo Real do Microsoft Defender Antivírus encontrou um erro e falhou.
Recurso: Em Tempo de Acesso
Código do Erro: 0x8007043c
Descrição do erro: Não é possível compartilhar este serviço no modo de segurança
Motivo: A inteligência de segurança antimalware parou de funcionar por um motivo desconhecido. Em alguns casos, reiniciar o serviço pode resolver o problema.

Date: 2024-03-15 18:38:50
Description:
Microsoft Defender Antivírus encontrou um erro ao tentar atualizar a inteligência de segurança.
Nova Versão da Inteligência de Segurança:
Versão da Inteligência de Segurança anterior: 1.407.454.0
Fonte da Atualização: Servidor do Microsoft Update
Tipo da Inteligência de Segurança: Antivírus
Tipo da atualização: Completa
Usuário: AUTORIDADE NT\SISTEMA
Versão Atual do Mecanismo:
Versão Anterior do Mecanismo: 1.1.24020.9
Código de Erro: 0x8007043c
Descrição do Erro: Não é possível compartilhar este serviço no modo de segurança 

CodeIntegrity:
===============
Date: 2024-07-26 20:36:33
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Mozilla Firefox\firefox.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\TubeDigger\TbdgHook64.dll that did not meet the Microsoft signing level requirements.


==================== Informações da Memória ===========================

BIOS: American Megatrends Inc. 0701 06/23/2014
placa-mãe: ASUSTeK COMPUTER INC. A58M-A/BR
Processador: AMD A8-7650K Radeon R7, 10 Compute Cores 4C+6G
Percentagem de memória em uso: 42%
RAM física total: 7110.45 MB
RAM física disponível: 4072.74 MB
Virtual Total: 7558.45 MB
Virtual disponível: 4084.79 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:139.96 GB) (Free:17.61 GB) (Model: SSD 256GB) NTFS
Drive d: (Novo volume) (Fixed) (Total:97.66 GB) (Free:13.67 GB) (Model: SSD 256GB) NTFS
Drive e: (Novo volume) (Fixed) (Total:476.91 GB) (Free:431.31 GB) (Model: SSD 512GB) NTFS

\\?\Volume{cb800121-0000-0000-0000-100000000000}\ (Reservado pelo Sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
\\?\Volume{cb800121-0000-0000-0000-a06d3b000000}\ () (Fixed) (Total:0.76 GB) (Free:0.08 GB) NTFS
\\?\Volume{3657e3c3-0000-0000-0060-253a77000000}\ (VTOYEFI) (Fixed) (Total:0.03 GB) (Free:0 GB) FAT

==================== MBR & Tabela de Partições ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 238.5 GB) (Disk ID: CB800121)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=140 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=97.7 GB) - (Type=0F Extended)
Partition 4: (Not Active) - (Size=778 MB) - (Type=27)

==========================================================
Disk: 1 (Size: 476.9 GB) (Disk ID: 3657E3C3)
Partition 1: (Not Active) - (Size=476.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=32 MB) - (Type=EF)

==================== Fim de Addition.txt =======================




Tive que usar o recurso copiar e colar porque está dando erro ao tentar anexar arquivos.
Fico no aguardo de mais instruçoes e desde já agradeço pela atenção.
0

Análise de log HijackThis.

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 19:34:29, on 24/07/2024
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.19041.4355)


Boot mode: Normal

Running processes:
C:\Users\TURCA\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
O4 - HKCU\..\Run: [OneDrive] "C:\Users\TURCA\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [electron.app.BlueStacks Services] C:\Users\TURCA\AppData\Local\Programs\bluestacks-services\BlueStacksServices.exe --hidden
O4 - HKCU\..\Run: [SH_AutoBackup] C:\SHARMAQ\SHOficina\SHRecovery.exe /BACKUP
O4 - HKCU\..\Run: [EADM] "C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe" -silent
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [MicrosoftEdgeAutoLaunch_D9A72F260AB719B5E141D61BE42D2BB8] "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start
O4 - HKCU\..\Run: [EpicGamesLauncher] "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent -launchcontext=boot
O4 - HKCU\..\Run: [Viber] "C:\Users\TURCA\AppData\Local\Viber\Viber.exe" AutoStart
O4 - Global Startup: AdsPower.lnk = ?
O4 - Global Startup: SPDriverInstall.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{75fe8ff4-163f-4ae2-b58d-9cb9ca2ae8f9}: NameServer = 1.1.1.1,1.0.0.1
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD Crash Defender Service - Unknown owner - C:\Windows\System32\amdfendrsr.exe (file missing)
O23 - Service: AMD External Events Utility - AMD - C:\Windows\System32\DriverStore\FileRepository\u0393743.inf_amd64_52bb45d16658cef5\B393344\atiesrxx.exe
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CCleaner Performance Optimizer Service (CCleanerPerformanceOptimizerService) - Piriform Software Ltd - C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\Windows\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_5601b - Unknown owner - C:\Windows\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: EABackgroundService - Electronic Arts - C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epic Online Services (EpicOnlineServices) - Epic Games, Inc. - C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\GameInputSvc.exe,-101 (GameInputSvc) - Unknown owner - C:\Windows\System32\GameInputSvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) (GoogleChromeElevationService) - Google LLC - C:\Program Files\Google\Chrome\Application\126.0.6478.183\elevation_service.exe
O23 - Service: GoogleUpdater InternalService 128.0.6597.0 (GoogleUpdaterInternalService128.0.6597.0) (GoogleUpdaterInternalService128.0.6597.0) - Google LLC - C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe
O23 - Service: GoogleUpdater Service 128.0.6597.0 (GoogleUpdaterService128.0.6597.0) (GoogleUpdaterService128.0.6597.0) - Google LLC - C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Smart Windows Service (LmsaWindowsService) - Unknown owner - C:\Program Files\Rescue and Smart Assistant\LmsaWindowsService.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: MBVpnTunnelService - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\Windows\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: Rockstar Game Library Service (Rockstar Service) - Rockstar Games - C:\Program Files\Rockstar Games\Launcher\RockstarService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\steamservice.exe
O23 - Service: TeamViewer - TeamViewer Germany GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9903 bytes
1

App espionagem que não sai com reset

Estou tendo meu celular stalkeado, já fiz reset mas a pessoa continua obtendo informações das minhas conversas no Whatsapp e até pesquisas feitas na internet. Vi que existem aplicativos que não são removidos com o reset, o que faço? É possível monitorar o Whatsapp pelo acesso a rede wi-fi que estou conectada?
2

Suposto rootkit no roteador

Boa tarde!
Desde alguns meses atrás venho sofrendo com um vírus que mesmo formatando, retorna. (Talvez ele esteja no meu roteador?)
Esse danado infectou todos os meus dispositivos móveis e até mesmo minha tv. (Abrindo apps aleatoriamente e apagando textos feitos por mim do nada)
No Pc, ele abre páginas e janelas do CMD infinitamente parando do nada e nenhum antivírus consegue detectar...
Uso alguns pendrives para formatar, porém acredito que estes tbm estejam infectados com esse vírus, por isso que esse vírus volta.

Deixarei o log do ZHPcleaner upado no meu post...


Segue os logs:
https://www.cjoint.com/c/NEfwpMHtAGz
https://www.cjoint.com/c/NEfwrbBKe2z
0

Ataque Deauther

Boa noite.
Tenho Decos M5 em minha casa.
Alguém está me atacando com Deauther.
Sempre que tento reconectar, acabo desconectado.
Minhas câmeras estão fora, meus extensores também.
Acabei comprando um detector de ataques Deauther, que não para de tocar e sinalizar ataques.
Não sou da área, entendo um pouco.
Alguém pode me ajudar como posso resolver o problema?
Obrigado
1

Windows apaga programas não Microsoft sozinho.

Pessoal a um bom tempo venho enfrentando um problema que meu windows simplesmente apaga os programas instalados sozinho por exemplo...

https://imgur.com/a/nzxt-cam-41oymeh
77519

ontem a noite antes de desligar o pc este programa estava instalado e funcionando hoje ao ligar windows ele apareceu essa mensagem ao clicar no app.

o mais estranho que o pendrive é zerado e windows tambem recem baixado e quando instalo mesmo windows no pc de outras pessoas nao ocorre esses problemas !

alguem poderia me ajudar ? eu ja nao sei mais o que fazer

eu gostaria de adicionar uma infomacao adicional eu olhando o log percebi que ocorreu uma etapa de recuperacao no windows. será que ela que esa causando esse problema ?

https://imgur.com/a/recuperacao-4gBT9EC?third_party=1
77520
1

Estou com vírus SVchost.exe, formatei e não resolveu.

Estou com um Vírus SVchost no meu Pc, passei vários antivírus, Avast, malwarebytes, SFC/scannow, ComboCleaner e nada detectou o vírus. resolvi formata o computador, e aparentemente depois estava tudo limpo, quando eu abri o gerenciador de tarefas, e cliquei em algum "host de serviço" e fui em propriedades ali estava ele, O SVchost.exe havia sido criado e modificado uma hora depois de eu ter baixado e reinstalado o Windows. Cheguei nos PCs do meus amigos e todos eles estão com a data certa que seria de ‎"domingo, ‎3‎ de ‎dezembro‎ de ‎2023, ‏‎23:49:03" 


Anexo do post‎fora isso, tbm percebi um arquivo aparecendo no OneDrive, como "Default.rdp". Não sei por onde esse malware está entrando no meu Pc de novo. O negócio que eu baixei foi isso aqui, só fui notar meses depois quando eu joguei no vírus total:

https://www.virustotal.com/gui/file/e44751394191d344609f8a8de8223d8958f3cb2d91f7632663db137f2f5b1a2c/behavior

Desse processo de instalação desse pacote, eu me lembro do meu discord ter atualizado, minha área de trabalho tbm ter atualizado, e se eu não me engano, baixou algum arquivo isasetup.exe.

Não sei mais oq fazer.
2

Como saber se existe algum vírus no meu computador?

Fala pessoal, tudo bem?

Recentemente acabei baixando um trojan no meu computador, que ocasionou no hackeamento da minha conta do instagram.

Consegui recuperar a conta, e formatei meu pc, mas ainda tenho dúvida se ainda há possibilidade de haver um vírus escondido.

Se alguém puder me ajudar a identificar isso, ficarei eternamente agradecido!
0

Como fui infectado desse forma?

Boa noite, senhores! No dia 2 de abril eu baixei um aplicativo crakeado no Github. Mas para minha surpresa, não era um aplicativo, e sim um malware conhecido como RisePro. Encontrei esse site aqui depois de pesquisar casos iguais ao meu: https://www.cisoadvisor.com.br/hackers-disseminam-ladrao-de-informacoes-por-meio-do-github/. O erro foi meu de ter confiado nesses aplicativos. Mas eu tenho uma pergunta que até agora eu não que está na minha cabeça a um tempo. Como ele hackeou minha conta no jogo? Eu jogo um game chamado valorant, eu ativei a verificação de duas etapas na minha conta, mas de alguma forma ele conseguiu entrar na nela sem código que chega no meu email pra acessar minha conta. Ele não entrou no meu email da Microsoft, pois, eu também tenho a verificação de duas etapas e sempre chega um código na minha tela pra eu confirmar a entrada de qualquer pessoa. Podem tentar me dar alguma explicação de como ele pode ter burlado a verificação de duas etapas?
0

Vírus não sai nem formatando.

Ola, peço ajuda de voces para resolver um problema bem chato, a uns dias atras peguei um virus em que alguem fica falando no meu microfone, descobri isso porque estava em call com uns amigos e eles falavam pra eu parar com "isso" e que ja estava irritando, eu sem saber continuava perguntando o que eu estava fazendo, eles responderam que eu estava falando muito perto do microfone, então fui ver oq era na opção "ouvir sua voz" no discord, então ouvi alguem que definitivamente nao era eu falando, uma voz bem estourada e as palavras abafadas, mas era um voz. 
Alguns detalhes sao que meu headset é de celular, com adaptador para separar o fone do microfone, outro detalhe é que, ja tentei formatar pelo windows (restaurar) e pela bios mas nada funciona, nao tenho muita noção de como essas coisas funcionam, mas pensei que talvez o virus infecte o pen drive antes de formatar, ou que é um virus BIOS, ja vi em alguns lugares que os virus podem estar na placa de video tb. Ja pensei até em comprar outro computador, algo que é meio dificil agora. Pelo que me lembre é isso, caso aluguma duvida por favor perguntem
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal