Logo Hardware.com.br
etm
etm Membro Junior Registrado
82 Mensagens 18 Curtidas

[Resolvido] Facebook e páginas curtidas.

#1 Por etm 29/06/2021 - 12:47
Boa tarde,
Hoje eu me deparei com atividades que eu não fiz no facebook. Pelo que observei foi uma atividade desde o dia 08 de junho, curtindo páginas através do meu perfil, do tipo, com umas letras de idioma esquisita, talvez coreano, algo assim...Como não entro muito no facebook, só vim notar hoje, porque tinha postagens dessas páginas nas minhas notificações.
Sim, depois eu fui ver minhas configurações de privacidade...e alterei minha senha.
Além disso, só acesso meu facebook de um dispositivo e os IPs foram três diferentes.
O que mais posso fazer quanto a isso?
PH
PH Cyber Highlander Registrado
61.3K Mensagens 10.7K Curtidas
#2 Por PH
29/06/2021 - 15:27
etm disse:
Boa tarde,
Hoje eu me deparei com atividades que eu não fiz no facebook. Pelo que observei foi uma atividade desde o dia 08 de junho, curtindo páginas através do meu perfil, do tipo, com umas letras de idioma esquisita, talvez coreano, algo assim...Como não entro muito no facebook, só vim notar hoje, porque tinha postagens dessas páginas nas minhas notificações.
Sim, depois eu fui ver minhas configurações de privacidade...e alterei minha senha.
Além disso, só acesso meu facebook de um dispositivo e os IPs foram três diferentes.
O que mais posso fazer quanto a isso?


Boa tarde!

Primeira coisa que deve fazer é mudar a senha e ativar autenticação por dois fatores de autenticação. Não necessariamente seus dados foi obtidos invadindo o seu computador, veja essa notícia abaixo.

Mais de 533 milhões de contas no Facebook tiveram dados vazados

Dessa forma, os hackers tem todos os dados para acessar sua conta.

Essas redes sociais são muito visadas, então mude sua senha periodicamente, ativa a autenticação por dois fatores.

O que é a autenticação de dois fatores e como ela funciona no Facebook?

Siga as informações abaixo.

Faça download do Kaspersky Virus Removal Tool, é um antivírus on-line, ou seja, não precisa instalar.

Neste link a seguir, tem um pequeno tutorial de como usar o Kaspersky: https://www.hardware.com.br/comunidade/v-t/1510949/#post8249043

Poste o resultado aqui.

Depois gere logs para verificarmos o seu computador.

Problemas com vírus? Saiba como criar um tópico para análise.
Mas aquele que me negar diante dos homens, eu também o negarei diante do meu Pai que está nos céus.

Mateus 10:33
etm
etm Membro Junior Registrado
82 Mensagens 18 Curtidas
#4 Por etm
29/06/2021 - 19:12
Boa noite,



PH disse:
Boa tarde!

Primeira coisa que deve fazer é mudar a senha e ativar autenticação por dois fatores de autenticação. Não necessariamente seus dados foi obtidos invadindo o seu computador, veja essa notícia abaixo.

Mais de 533 milhões de contas no Facebook tiveram dados vazados

Dessa forma, os hackers tem todos os dados para acessar sua conta.

Essas redes sociais são muito visadas, então mude sua senha periodicamente, ativa a autenticação por dois fatores.

O que é a autenticação de dois fatores e como ela funciona no Facebook?

Siga as informações abaixo.

Faça download do Kaspersky Virus Removal Tool, é um antivírus on-line, ou seja, não precisa instalar.

Neste link a seguir, tem um pequeno tutorial de como usar o Kaspersky:
https://www.hardware.com.br/comunidade/v-t/1510949/#post8249043

Poste o resultado aqui.

Depois gere logs para verificarmos o seu computador.

Problemas com vírus? Saiba como criar um tópico para análise.
PH
PH Cyber Highlander Registrado
61.3K Mensagens 10.7K Curtidas
#5 Por PH
29/06/2021 - 19:23
etm disse:
Boa noite,

Imagem
https://ibb.co/bsfhdjG




Nada foi encontrado, rode a ferramenta para gerar log. Para analisarmos se tem algo suspeito.

Edit.

Gere o log seguindo esse tutorial.

Problemas com vírus? Saiba como criar um tópico para análise.
Mas aquele que me negar diante dos homens, eu também o negarei diante do meu Pai que está nos céus.

Mateus 10:33
etm
etm Membro Junior Registrado
82 Mensagens 18 Curtidas
#6 Por etm
30/06/2021 - 12:05
Gere o log seguindo esse tutorial.

Bom dia!!
"FRST"

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 29-06-2021
Executado por gjoas (administrador) em DESKTOP-8HDMRDB (ASUSTeK COMPUTER INC. S400CA) (30-06-2021 09:34:57)
Executando a partir de C:\Users\gjoas\Downloads
Perfis Carregados: gjoas
Platform: Windows 10 Home Single Language Versão 21H1 19043.1081 (X64) Idioma: Português (Brasil)
Navegador padrão: Edge
Modo da Inicialização: Normal

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <17>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2106.14307.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowsstore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\UtcDecoderHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe

==================== Registro (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\System32\DptfPolicyLpmServiceHelper.exe [27024 2013-01-18] (Intel Corporation -> Intel Corporation)
HKU\S-1-5-21-1057953001-4059818014-1656454705-1001\...\Run: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe [1976184 2021-06-20] (Microsoft Corporation -> Microsoft Corporation)

==================== Tarefas Agendadas (Whitelisted) ============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

Task: {22727AE8-E26C-4167-A20F-64FC7D83770A} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [147320 2021-06-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {299B77D9-0267-4877-8169-132E874726F0} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [2822520 2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {3C249585-0CD4-4B69-982C-3D8E07A429A0} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1510832 2021-06-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {52B45835-60DC-4AD7-A719-B5ADA3D1B00D} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122168 2015-03-10] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {5FD1FEE5-014E-47A8-9494-32791FBF294C} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23124896 2021-06-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {75A4D9D5-A929-4B54-ACBB-07E079E5D607} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [143160 2019-03-12] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
Task: {834A6D2A-EC1C-44B0-AE8C-CEB428E5C4E8} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [147320 2021-06-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {9B653DAD-BDCB-49F7-9995-BBC7CCC3C941} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3618096 2021-03-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {A97837C9-1F6F-4EF9-A236-CCBD91F53192} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3618096 2021-03-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {C60BF910-6BCD-4B40-9D60-10E3DC12D089} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3618096 2021-03-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {EE743552-44E1-4B5E-9EEB-0376C3C61820} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122168 2015-03-10] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {F2790F86-D8AC-45BB-A41C-B6AA2FD7B606} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18232 2015-06-30] (ASUSTeK Computer Inc. -> AsusTek)
Task: {FA904613-EB6A-4CFA-81D2-296BF1CA169B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23124896 2021-06-17] (Microsoft Corporation -> Microsoft Corporation)

(Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.)


==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9b4332d2-6336-43b3-808a-c68f0ec11847}: [DhcpNameServer] 192.168.1.1

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\gjoas\AppData\Local\Microsoft\Edge\User Data\Default [2021-06-30]
Edge Notifications: Default -> hxxps://forumpcbrasil.forumeiros.com; hxxps://meet.google.com; hxxps://web.digitalinnovation.one; hxxps://www.climaaovivo.com.br; hxxps://www.novamulher.com
Edge Extension: (Ghostery – Bloqueador de anúncios para privacidade) - C:\Users\gjoas\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fclbdkbhjlgkbpfldjodgjncejkkjcme [2021-06-18]

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)

==================== Serviços (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11279752 2021-06-17] (Microsoft Corporation -> Microsoft Corporation)
S4 DptfParticipantProcessorService; C:\WINDOWS\System32\DptfParticipantProcessorService.exe [31632 2013-01-18] (Intel Corporation -> Intel Corporation)
S4 DptfPolicyConfigTDPService; C:\WINDOWS\System32\DptfPolicyConfigTDPService.exe [33168 2013-01-18] (Intel Corporation -> Intel Corporation)
S4 DptfPolicyCriticalService; C:\WINDOWS\System32\DptfPolicyCriticalService.exe [32656 2013-01-18] (Intel Corporation -> Intel Corporation)
S4 DptfPolicyLpmService; C:\WINDOWS\System32\DptfPolicyLpmService.exe [39824 2013-01-18] (Intel Corporation -> Intel Corporation)
S3 FileSyncHelper; C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\FileSyncHelper.exe [2262904 2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [288360 2021-06-22] (HP Inc. -> HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7391408 2021-06-20] (Malwarebytes Inc -> Malwarebytes)
S3 OneDrive Updater Service; C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\OneDriveUpdaterService.exe [2728312 2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2105.5-0\NisSrv.exe [2644776 2021-06-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2105.5-0\MsMpEng.exe [136656 2021-06-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WsAppService3; C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe [83232 2019-06-26] (Wondershare Technology Co.,Ltd -> Wondershare)
S2 ElevationService; C:\Program Files (x86)\Wondershare\MobileTrans (Português)\ElevationService.exe [X]

===================== Drivers (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 AmUStor; C:\WINDOWS\system32\drivers\AmUStor.SYS [95232 2012-10-03] (Microsoft Windows Hardware Compatibility Publisher -> Alcor Micro, Corp.)
S3 AsusTP; C:\WINDOWS\System32\drivers\AsusTP.sys [100776 2015-06-30] (ASUSTeK Computer Inc. -> ASUS Corporation)
R3 ATP; C:\WINDOWS\System32\drivers\AsusTP.sys [100776 2015-06-30] (ASUSTeK Computer Inc. -> ASUS Corporation)
R3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 DptfDevDram; C:\WINDOWS\System32\drivers\DptfDevDram.sys [107920 2013-01-18] (Intel Corporation -> Intel Corporation)
S3 DptfDevFan; C:\WINDOWS\System32\drivers\DptfDevFan.sys [43408 2013-01-18] (Intel Corporation -> Intel Corporation)
S3 DptfDevGen; C:\WINDOWS\System32\drivers\DptfDevGen.sys [65424 2013-01-18] (Intel Corporation -> Intel Corporation)
S3 DptfDevPch; C:\WINDOWS\System32\drivers\DptfDevPch.sys [97680 2013-01-18] (Intel Corporation -> Intel Corporation)
S3 DptfDevProc; C:\WINDOWS\System32\drivers\DptfDevProc.sys [229776 2013-01-18] (Intel Corporation -> Intel Corporation)
S3 DptfManager; C:\WINDOWS\System32\drivers\DptfManager.sys [363920 2013-01-18] (Intel Corporation -> Intel Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [199128 2021-06-19] (Malwarebytes Inc -> Malwarebytes)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32696 2020-11-19] (ASUSTek Computer Inc. -> ASUS)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [14992 2012-08-02] (ASUSTeK Computer Inc. -> )
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220752 2021-06-23] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-06-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [198888 2021-06-23] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [69016 2021-06-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-06-23] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [156880 2021-06-27] (Malwarebytes Inc -> Malwarebytes)
S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssuddmgr; C:\WINDOWS\System32\drivers\ssuddmgr.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
R3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ssudobex; C:\WINDOWS\System32\drivers\ssudobex.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64880 2020-11-11] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated)
S3 ssudrmnet; C:\WINDOWS\System32\drivers\ssudrmnet.sys [70400 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.)
S3 ssudserd; C:\WINDOWS\System32\drivers\ssudserd.sys [206080 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ss_conn_usb_driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [26368 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49568 2021-06-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [425184 2021-06-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [76000 2021-06-18] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um mês (criados) (Whitelisted) =========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2021-06-30 09:34 - 2021-06-30 09:37 - 000015034 _____ C:\Users\gjoas\Downloads\FRST.txt
2021-06-30 09:33 - 2021-06-30 09:34 - 002300416 _____ (Farbar) C:\Users\gjoas\Downloads\FRST64.exe
2021-06-29 22:48 - 2021-06-29 22:57 - 000000017 _____ C:\Users\gjoas\Desktop\amigo.txt
2021-06-29 22:47 - 2021-06-29 23:03 - 000000242 _____ C:\Users\gjoas\.bash_history
2021-06-29 22:45 - 2021-06-29 22:45 - 000000006 _____ C:\Users\gjoas\Documents\amigo.txt
2021-06-29 21:43 - 2021-06-29 21:43 - 000001766 _____ C:\Users\Public\Desktop\Git Bash.lnk
2021-06-29 21:43 - 2021-06-29 21:43 - 000001766 _____ C:\ProgramData\Desktop\Git Bash.lnk
2021-06-29 21:43 - 2021-06-29 21:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Git
2021-06-29 21:42 - 2021-06-29 21:43 - 000000000 ____D C:\Program Files\Git
2021-06-29 21:38 - 2021-06-29 21:39 - 051179176 _____ (The Git Development Community ) C:\Users\gjoas\Downloads\Git-2.32.0-64-bit.exe
2021-06-29 16:53 - 2021-06-29 16:53 - 000309104 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_393a6734a_klark.sys
2021-06-29 16:53 - 2021-06-29 16:53 - 000224880 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_393a6734a_mark.sys
2021-06-29 16:53 - 2021-06-29 16:53 - 000127792 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\393a6734.sys
2021-06-29 16:52 - 2021-06-29 16:52 - 000000000 ____D C:\KVRT2020_Data
2021-06-28 21:42 - 2021-06-28 21:52 - 000000000 ____D C:\Users\gjoas\Desktop\Ana Elizabete
2021-06-27 16:45 - 2021-06-27 16:45 - 000000000 ____D C:\ProgramData\Wondershare
2021-06-27 16:44 - 2021-06-27 16:48 - 000000000 ____D C:\Program Files (x86)\Wondershare
2021-06-27 16:44 - 2021-06-27 16:47 - 000000000 ____D C:\Users\gjoas\AppData\Roaming\Wondershare
2021-06-27 16:42 - 2021-06-27 16:46 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2021-06-27 10:33 - 2021-06-27 10:33 - 000156880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2021-06-27 10:33 - 2021-06-27 10:33 - 000069016 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2021-06-27 09:26 - 2021-06-27 09:26 - 000452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-06-27 09:26 - 2021-06-27 09:26 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2021-06-27 09:25 - 2021-06-27 09:25 - 002371072 _____ C:\WINDOWS\system32\rdpnano.dll
2021-06-27 09:25 - 2021-06-27 09:25 - 001314128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-06-27 09:25 - 2021-06-27 09:25 - 000570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-06-27 09:25 - 2021-06-27 09:25 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2021-06-27 09:25 - 2021-06-27 09:25 - 000011333 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-06-27 09:24 - 2021-06-27 09:24 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2021-06-27 09:24 - 2021-06-27 09:24 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-06-27 09:24 - 2021-06-27 09:24 - 001393504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-06-27 09:24 - 2021-06-27 09:24 - 000097792 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-06-27 09:24 - 2021-06-27 09:24 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2021-06-26 19:07 - 2021-06-26 20:36 - 000000000 ____D C:\Users\gjoas\.portugol
2021-06-26 19:07 - 2021-06-26 19:07 - 000000000 ____D C:\ProgramData\Oracle
2021-06-26 19:04 - 2021-06-26 19:04 - 000002615 _____ C:\Users\Public\Desktop\Portugol Studio.lnk
2021-06-26 19:04 - 2021-06-26 19:04 - 000002615 _____ C:\ProgramData\Desktop\Portugol Studio.lnk
2021-06-26 19:04 - 2021-06-26 19:04 - 000000000 ____D C:\ProgramData\UNIVALI
2021-06-26 19:04 - 2021-06-26 19:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Portugol Studio
2021-06-26 16:08 - 2021-06-26 16:08 - 000002601 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flowgorithm.lnk
2021-06-26 16:08 - 2021-06-26 16:08 - 000002589 _____ C:\Users\Public\Desktop\Flowgorithm.exe.lnk
2021-06-26 16:08 - 2021-06-26 16:08 - 000002589 _____ C:\ProgramData\Desktop\Flowgorithm.exe.lnk
2021-06-26 16:08 - 2021-06-26 16:08 - 000000000 ____D C:\Program Files\Flowgorithm
2021-06-26 16:06 - 2021-06-26 16:06 - 000000000 ____D C:\Users\gjoas\Downloads\Flowgorithm-2.29.0-64-Setup
2021-06-25 13:22 - 2021-06-25 13:22 - 000581348 _____ C:\Users\gjoas\Downloads\1_5084574927172928099.pdf
2021-06-23 09:11 - 2021-06-23 09:11 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-06-23 09:11 - 2021-06-23 09:11 - 000220752 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-06-23 09:11 - 2021-06-23 09:11 - 000198888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2021-06-23 08:15 - 2021-06-25 13:05 - 000000000 ____D C:\Users\gjoas\Desktop\CADERNETAS E CONTEÚDOS
2021-06-22 23:38 - 2021-06-22 23:38 - 000016636 _____ C:\Users\gjoas\Downloads\Captura da Web_22-6-2021_23385_lms.ev.org.br.jpeg
2021-06-22 20:41 - 2021-06-22 20:41 - 000101223 _____ C:\Users\gjoas\Downloads\Captura da Web_22-6-2021_20417_meet.google.com.jpeg
2021-06-22 14:03 - 2021-06-22 14:03 - 000000000 ____D C:\ProgramData\HP
2021-06-22 14:00 - 2021-06-22 14:00 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2021-06-22 13:21 - 2021-06-22 13:21 - 000031747 _____ C:\Users\gjoas\Downloads\WhatsApp Image 2021-06-22 at 1.15.56 PM.jpeg
2021-06-21 18:35 - 2021-06-21 18:35 - 000183498 _____ C:\Users\gjoas\Downloads\Captura da Web_21-6-2021_183541_www.speedtest.net.jpeg
2021-06-21 14:16 - 2021-06-21 14:17 - 000000000 ____D C:\Users\gjoas\Documents\Splendid_Upgrade_Win10_VER3130004
2021-06-21 14:08 - 2021-06-21 14:08 - 000003646 _____ C:\WINDOWS\system32\Tasks\ATK Package 36D18D69AFC3
2021-06-21 14:08 - 2021-06-21 14:08 - 000002874 _____ C:\WINDOWS\system32\Tasks\ATK Package A22126881260
2021-06-21 14:06 - 2021-06-21 14:06 - 000000000 ____D C:\Users\gjoas\Documents\ATKPackage_Win10_64_VER100039
2021-06-21 14:05 - 2021-06-21 14:06 - 012379704 _____ C:\Users\gjoas\Documents\ATKPackage_Win10_64_VER100039.zip
2021-06-21 14:01 - 2021-06-30 08:11 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2021-06-21 13:46 - 2021-06-21 13:46 - 000003628 _____ C:\WINDOWS\system32\Tasks\ASUS Smart Gesture Launcher
2021-06-21 13:46 - 2021-06-21 13:46 - 000000000 ____D C:\Program Files\DIFX
2021-06-21 13:43 - 2021-06-21 13:43 - 000000000 ____D C:\Users\gjoas\Documents\SmartGesture_WIN10_64_VER405
2021-06-21 10:51 - 2021-06-24 09:47 - 000000000 ____D C:\Users\gjoas\AppData\Local\CrashDumps
2021-06-21 10:50 - 2021-06-21 14:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2021-06-21 10:50 - 2021-06-21 14:21 - 000000000 ____D C:\Program Files (x86)\ASUS
2021-06-21 10:47 - 2021-06-21 10:48 - 000003980 _____ C:\WINDOWS\system32\Tasks\Update Checker
2021-06-21 10:45 - 2021-06-21 10:47 - 000000000 ____D C:\Users\gjoas\Documents\ALU_3.6.8
2021-06-21 10:43 - 2021-06-21 10:45 - 011797169 _____ C:\Users\gjoas\Documents\ALU_3.6.8.zip
2021-06-20 17:56 - 2021-06-27 10:40 - 000000000 ____D C:\Users\gjoas\Documents\Gravações de som
2021-06-20 16:31 - 2021-06-20 16:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
2021-06-20 16:31 - 2017-11-24 09:16 - 004321160 _____ (Qualcomm Atheros Communications, Inc.) C:\WINDOWS\system32\Drivers\athw10x.sys
2021-06-20 16:29 - 2021-03-17 18:38 - 001382144 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000964944 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000873368 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000541024 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000231832 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000230608 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000218176 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000174848 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000158600 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000090832 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000088232 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000083536 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2021-06-20 16:29 - 2021-03-17 18:38 - 000075448 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
2021-06-20 16:29 - 2021-03-17 18:37 - 072520616 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2021-06-20 16:29 - 2021-03-17 18:37 - 003676976 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2021-06-20 16:29 - 2021-03-17 18:37 - 003159680 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2021-06-20 16:29 - 2021-03-17 18:37 - 000343600 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2021-06-20 16:29 - 2021-03-17 18:13 - 045120758 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2021-06-20 16:28 - 2021-03-17 18:37 - 003601376 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 003375920 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000692056 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000453184 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000392760 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000327176 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000327176 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000220280 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000157248 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000139664 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000116432 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000093800 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2021-06-20 16:28 - 2021-03-17 18:37 - 000090080 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 007178376 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 007101664 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 002930056 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 001971280 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 001787864 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 001598304 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 001516184 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000751216 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000734680 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000715552 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000511552 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000452656 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000448520 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000332920 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000278184 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000261152 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000261104 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000260120 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2021-06-20 16:28 - 2021-03-17 18:36 - 000122232 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2021-06-20 16:27 - 2018-09-13 09:22 - 000480176 _____ (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\IntcDAud.sys
2021-06-20 14:31 - 2021-06-20 14:31 - 000003216 _____ C:\WINDOWS\system32\Tasks\RTKCPL
2021-06-20 14:31 - 2021-06-20 14:31 - 000003202 _____ C:\WINDOWS\system32\Tasks\RtHDVBg
2021-06-20 14:29 - 2021-03-17 18:37 - 006426616 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2021-06-20 14:29 - 2021-03-17 18:37 - 003843944 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2021-06-20 14:29 - 2021-03-17 18:37 - 000192872 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2021-06-20 14:29 - 2021-03-17 18:37 - 000023600 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2021-06-20 14:29 - 2017-06-29 18:55 - 000677664 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll
2021-06-20 14:29 - 2017-06-29 18:54 - 004059960 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll
2021-06-20 14:29 - 2017-06-29 18:54 - 001166152 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO4064.dll
2021-06-20 14:29 - 2017-06-29 18:54 - 000678176 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll
2021-06-20 14:29 - 2017-06-29 18:54 - 000618184 _____ (Knowles Acoustics ) C:\WINDOWS\system32\KAAPORT64.dll
2021-06-20 14:29 - 2017-06-29 18:54 - 000514520 _____ (DTS) C:\WINDOWS\system32\DTSU2PLFX64.dll
2021-06-20 14:29 - 2017-06-29 18:54 - 000500552 _____ (DTS) C:\WINDOWS\system32\DTSU2PGFX64.dll
2021-06-20 14:29 - 2017-06-29 18:54 - 000428224 _____ (DTS) C:\WINDOWS\system32\DTSU2PREC64.dll
2021-06-20 14:29 - 2017-06-29 18:54 - 000330552 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll
2021-06-20 14:29 - 2017-06-29 18:51 - 002050176 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll
2021-06-20 14:28 - 2021-06-20 14:28 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2021-06-20 14:28 - 2021-06-20 14:28 - 000000000 ____D C:\Program Files (x86)\Realtek
2021-06-20 14:28 - 2017-06-29 18:52 - 000574752 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll
2021-06-20 14:28 - 2017-06-29 18:52 - 000118592 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll
2021-06-20 14:27 - 2021-06-20 14:32 - 000000000 ___HD C:\Program Files (x86)\Temp
2021-06-20 14:27 - 2016-09-22 14:55 - 002839520 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll
2021-06-20 10:43 - 2021-06-20 14:22 - 264424269 _____ (Realtek Semiconductor Corp.) C:\Users\gjoas\Documents\0009-64bit_Win7_Win8_Win81_Win10_R282.exe
2021-06-20 09:08 - 2021-06-20 09:08 - 033908397 _____ C:\Users\gjoas\Documents\le-cordon-bleu.pdf.pdf.pdf
2021-06-20 07:58 - 2021-06-20 07:58 - 000000000 ____D C:\Users\gjoas\AppData\Local\OneDrive
2021-06-19 16:33 - 2021-06-20 07:59 - 000003206 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2021-06-19 16:33 - 2021-06-20 07:59 - 000002182 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-06-19 16:33 - 2021-06-19 16:33 - 000000000 ___RD C:\Users\Default\OneDrive
2021-06-19 16:32 - 2021-06-21 07:31 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive
2021-06-19 16:31 - 2021-06-19 16:31 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2021-06-19 16:29 - 2021-06-19 16:29 - 000002485 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2021-06-19 16:29 - 2021-06-19 16:29 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2021-06-19 16:29 - 2021-06-19 16:29 - 000002434 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2021-06-19 16:29 - 2021-06-19 16:29 - 000002431 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2021-06-19 16:29 - 2021-06-19 16:29 - 000002421 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk
2021-06-19 16:29 - 2021-06-19 16:29 - 000002417 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2021-06-19 16:29 - 2021-06-19 16:29 - 000002401 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2021-06-19 16:14 - 2021-06-23 07:10 - 000000000 ____D C:\Program Files\Microsoft Office
2021-06-19 16:14 - 2021-06-19 16:14 - 000000000 ____D C:\Program Files\Microsoft Office 15
2021-06-19 16:08 - 2021-06-30 08:13 - 000004184 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{69862859-D4D9-4D09-BFD0-38D5875E8D53}
2021-06-19 15:50 - 2021-06-19 15:50 - 000000000 ____D C:\Users\gjoas\AppData\Roaming\Apowersoft
2021-06-19 15:50 - 2021-06-19 15:50 - 000000000 ____D C:\Program Files (x86)\Apowersoft
2021-06-19 15:13 - 2021-06-19 15:13 - 000000000 ____D C:\Users\gjoas\AppData\LocalLow\IObit
2021-06-19 15:12 - 2021-06-19 15:12 - 000000000 ____D C:\ProgramData\ProductData
2021-06-19 15:11 - 2021-06-19 15:11 - 000000000 ____D C:\Program Files (x86)\IObit
2021-06-19 12:45 - 2021-06-21 16:42 - 000000000 ____D C:\Users\gjoas\Documents\fotos do terceiro ano de Esther
2021-06-19 11:07 - 2021-06-20 08:02 - 000002035 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-06-19 11:07 - 2021-06-20 08:02 - 000002023 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2021-06-19 11:07 - 2021-06-20 08:02 - 000002023 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2021-06-19 11:07 - 2021-06-19 11:07 - 000000000 ____D C:\Users\gjoas\AppData\Local\mbam
2021-06-19 11:07 - 2021-06-19 11:06 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-06-19 11:07 - 2021-06-19 11:06 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-06-19 11:06 - 2021-06-19 11:06 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-06-19 11:05 - 2021-06-19 11:05 - 000000000 ____D C:\Program Files\Malwarebytes
2021-06-19 11:03 - 2021-06-19 15:14 - 000000000 ____D C:\Users\gjoas\AppData\Roaming\IObit
2021-06-19 11:03 - 2021-06-19 15:13 - 000000000 ____D C:\ProgramData\IObit
2021-06-18 20:52 - 2021-06-21 10:51 - 000000000 ____D C:\ProgramData\ASUS
2021-06-18 16:18 - 2021-06-18 16:18 - 000000000 ____D C:\Users\gjoas\AppData\LocalLow\Temp
2021-06-18 16:11 - 2021-06-18 16:11 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2021-06-18 15:48 - 2021-06-18 16:20 - 000000000 ____D C:\Users\gjoas\AppData\Roaming\Easeware
2021-06-18 14:21 - 2021-06-18 14:21 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2021-06-18 10:35 - 2021-06-19 15:02 - 000000000 ____D C:\Users\gjoas\AppData\Local\D3DSCache
2021-06-18 10:33 - 2021-06-18 10:33 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-06-18 10:26 - 2021-06-18 10:29 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-06-18 09:31 - 2021-06-18 09:31 - 000000307 _____ C:\Users\gjoas\Documents\fixlist.txt
2021-06-18 07:54 - 2021-06-18 16:40 - 000000000 ____D C:\Users\gjoas\AppData\Local\ElevatedDiagnostics
2021-06-18 06:43 - 2021-06-18 06:49 - 000000000 ____D C:\Users\gjoas\AppData\Local\PackageStaging
2021-06-18 06:37 - 2021-06-21 05:51 - 000000000 ____D C:\Users\gjoas\AppData\Local\Comms
2021-06-18 06:30 - 2021-06-18 06:30 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
2021-06-18 06:28 - 2021-06-22 13:59 - 000000000 ____D C:\Users\gjoas\AppData\Local\PlaceholderTileLogoFolder
2021-06-18 06:27 - 2021-06-18 06:27 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2021-06-18 06:24 - 2021-06-22 13:59 - 000000000 ____D C:\ProgramData\Packages
2021-06-18 06:24 - 2021-06-18 06:24 - 000000000 ____D C:\Users\gjoas\AppData\Local\Publishers
2021-06-18 06:21 - 2021-06-22 14:58 - 000000000 ____D C:\Users\gjoas\AppData\Local\Packages
2021-06-18 06:21 - 2021-06-18 10:02 - 000000000 ____D C:\Users\gjoas\AppData\Local\ConnectedDevicesPlatform
2021-06-18 06:21 - 2021-06-18 06:21 - 000000020 ___SH C:\Users\gjoas\ntuser.ini
2021-06-18 06:21 - 2021-06-18 06:21 - 000000000 ____D C:\Users\gjoas\AppData\Roaming\Adobe
2021-06-18 06:21 - 2021-06-18 06:21 - 000000000 ____D C:\Users\gjoas\AppData\Local\VirtualStore
2021-06-18 02:26 - 2021-06-18 02:26 - 000000000 _SHDL C:\Users\Usuário Padrão
2021-06-18 02:26 - 2021-06-18 02:26 - 000000000 _SHDL C:\Users\Todos os Usuários
2021-06-18 02:26 - 2021-06-18 02:26 - 000000000 _SHDL C:\Users\Default\AppData\Local\Histórico
2021-06-18 02:26 - 2021-06-18 02:26 - 000000000 _SHDL C:\Users\Default\AppData\Local\Dados de Aplicativos
2021-06-18 02:26 - 2021-06-18 02:26 - 000000000 _SHDL C:\ProgramData\Modelos
2021-06-18 02:26 - 2021-06-18 02:26 - 000000000 _SHDL C:\ProgramData\Menu Iniciar
2021-06-18 02:26 - 2021-06-18 02:26 - 000000000 _SHDL C:\ProgramData\Documentos
2021-06-18 02:26 - 2021-06-18 02:26 - 000000000 _SHDL C:\ProgramData\Dados de Aplicativos
2021-06-18 02:26 - 2021-06-18 02:26 - 000000000 _SHDL C:\Program Files\Common Files\Sistema
2021-06-18 02:26 - 2021-06-18 02:26 - 000000000 _SHDL C:\Program Files\Arquivos Comuns
2021-06-18 02:21 - 2021-06-27 10:39 - 001651882 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-06-18 02:03 - 2021-06-29 22:47 - 000000000 ____D C:\Users\gjoas
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\Modelos
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\Meus Documentos
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\Menu Iniciar
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\Documents\Minhas Músicas
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\Documents\Minhas Imagens
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\Documents\Meus Vídeos
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\Dados de Aplicativos
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\Configurações Locais
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\AppData\Local\Histórico
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\AppData\Local\Dados de Aplicativos
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\Ambiente de Rede
2021-06-18 02:03 - 2021-06-18 02:03 - 000000000 _SHDL C:\Users\gjoas\Ambiente de Impressão
2021-06-18 01:43 - 2021-06-20 16:31 - 000094215 _____ C:\WINDOWS\system32\Drivers\RTWAVES30.dat
2021-06-18 01:43 - 2021-06-18 01:43 - 000003260 _____ C:\WINDOWS\system32\Tasks\RtHDVBg_ListenToDevice
2021-06-18 01:43 - 2021-06-18 01:43 - 000000000 ____H C:\ProgramData\DP45977C.lfl
2021-06-18 01:42 - 2021-06-20 16:31 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2021-06-18 01:42 - 2021-06-18 01:42 - 000000000 ____D C:\Program Files\Realtek
2021-06-18 01:40 - 2021-06-29 16:51 - 000003618 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-06-18 01:40 - 2021-06-29 16:51 - 000003494 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-06-18 01:38 - 2021-06-27 10:32 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-06-18 01:38 - 2021-06-18 08:23 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-06-18 01:27 - 2021-06-30 08:45 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-06-18 01:27 - 2021-06-27 10:33 - 000438888 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-06-18 01:26 - 2021-06-18 01:26 - 000000000 ____D C:\WINDOWS\OEM
2021-06-18 01:24 - 2021-06-18 02:42 - 000000000 ____D C:\WINDOWS\Panther
2021-06-18 01:10 - 2021-06-18 02:42 - 000000000 ____D C:\Windows.old
2021-06-18 01:09 - 2021-06-18 01:09 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2021-06-18 01:04 - 2021-06-18 01:04 - 000000000 ____D C:\ProgramData\ssh
2021-06-18 00:52 - 2021-06-18 00:52 - 001687040 _____ C:\WINDOWS\system32\libcrypto.dll
2021-06-18 00:51 - 2021-06-18 00:51 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2021-06-18 00:51 - 2021-06-18 00:51 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2021-06-18 00:51 - 2021-06-18 00:51 - 000095744 _____ C:\WINDOWS\system32\VirtualMonitorManager.dll
2021-06-18 00:50 - 2021-06-18 00:50 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-06-18 00:50 - 2021-06-18 00:50 - 000700928 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2021-06-18 00:50 - 2021-06-18 00:50 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2021-06-18 00:50 - 2021-06-18 00:50 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2021-06-18 00:50 - 2021-06-18 00:50 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2021-06-18 00:50 - 2021-06-18 00:50 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpg2splt.ax
2021-06-18 00:50 - 2021-06-18 00:50 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2021-06-18 00:50 - 2021-06-18 00:50 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpg2splt.ax
2021-06-18 00:50 - 2021-06-18 00:50 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\VBICodec.ax
2021-06-18 00:50 - 2021-06-18 00:50 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VBICodec.ax
2021-06-18 00:50 - 2021-06-18 00:50 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2021-06-18 00:50 - 2021-06-18 00:50 - 000053760 _____ C:\WINDOWS\SysWOW64\BWContextHandler.dll
2021-06-18 00:50 - 2021-06-18 00:50 - 000045880 _____ C:\WINDOWS\system32\HvSocket.dll
2021-06-18 00:49 - 2021-06-18 00:49 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll
2021-06-18 00:49 - 2021-06-18 00:49 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-06-18 00:49 - 2021-06-18 00:49 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll
2021-06-18 00:49 - 2021-06-18 00:49 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll
2021-06-18 00:49 - 2021-06-18 00:49 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll
2021-06-18 00:49 - 2021-06-18 00:49 - 000729600 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2021-06-18 00:49 - 2021-06-18 00:49 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2021-06-18 00:49 - 2021-06-18 00:49 - 000178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2021-06-18 00:49 - 2021-06-18 00:49 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncpa.cpl
2021-06-18 00:49 - 2021-06-18 00:49 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2021-06-18 00:49 - 2021-06-18 00:49 - 000067072 _____ C:\WINDOWS\system32\BWContextHandler.dll
2021-06-18 00:49 - 2021-06-18 00:49 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll
2021-06-18 00:48 - 2021-06-18 00:48 - 001864192 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll
2021-06-18 00:48 - 2021-06-18 00:48 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2021-06-18 00:48 - 2021-06-18 00:48 - 000611952 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
2021-06-18 00:48 - 2021-06-18 00:48 - 000468440 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2021-06-18 00:48 - 2021-06-18 00:48 - 000446976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2021-06-18 00:48 - 2021-06-18 00:48 - 000235520 _____ C:\WINDOWS\SysWOW64\HeatCore.dll
2021-06-18 00:48 - 2021-06-18 00:48 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
2021-06-18 00:48 - 2021-06-18 00:48 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\activeds.tlb
2021-06-18 00:48 - 2021-06-18 00:48 - 000047472 _____ C:\WINDOWS\SysWOW64\umpdc.dll
2021-06-18 00:48 - 2021-06-18 00:48 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2021-06-18 00:47 - 2021-06-18 00:47 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll
2021-06-18 00:47 - 2021-06-18 00:47 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll
2021-06-18 00:47 - 2021-06-18 00:47 - 001163776 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-06-18 00:47 - 2021-06-18 00:47 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll
2021-06-18 00:47 - 2021-06-18 00:47 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll
2021-06-18 00:47 - 2021-06-18 00:47 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-06-18 00:47 - 2021-06-18 00:47 - 000330752 _____ C:\WINDOWS\SysWOW64\ssdm.dll
2021-06-18 00:47 - 2021-06-18 00:47 - 000266240 _____ C:\WINDOWS\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll
2021-06-18 00:47 - 2021-06-18 00:47 - 000240640 _____ C:\WINDOWS\SysWOW64\CoreMas.dll
2021-06-18 00:47 - 2021-06-18 00:47 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-06-18 00:47 - 2021-06-18 00:47 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\timedate.cpl
2021-06-18 00:47 - 2021-06-18 00:47 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncpa.cpl
2021-06-18 00:47 - 2021-06-18 00:47 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll
2021-06-18 00:47 - 2021-06-18 00:47 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msacm32.drv
2021-06-18 00:47 - 2021-06-18 00:47 - 000010752 _____ C:\WINDOWS\SysWOW64\agentactivationruntimestarter.exe
2021-06-18 00:46 - 2021-06-18 00:46 - 002254336 _____ C:\WINDOWS\system32\dwmscene.dll
2021-06-18 00:46 - 2021-06-18 00:46 - 000544768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2021-06-18 00:46 - 2021-06-18 00:46 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2021-06-18 00:46 - 2021-06-18 00:46 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2021-06-18 00:46 - 2021-06-18 00:46 - 000190976 _____ C:\WINDOWS\system32\BthpanContextHandler.dll
2021-06-18 00:46 - 2021-06-18 00:46 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2021-06-18 00:46 - 2021-06-18 00:46 - 000001370 _____ C:\WINDOWS\system32\ThirdPartyNoticesBySHS.txt
2021-06-18 00:45 - 2021-06-18 00:45 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2021-06-18 00:45 - 2021-06-18 00:45 - 000657464 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2021-06-18 00:45 - 2021-06-18 00:45 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-06-18 00:45 - 2021-06-18 00:45 - 000152064 _____ C:\WINDOWS\system32\EoAExperiences.exe
2021-06-18 00:45 - 2021-06-18 00:45 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\activeds.tlb
2021-06-18 00:45 - 2021-06-18 00:45 - 000029696 _____ (The ICU Project) C:\WINDOWS\system32\icuuc.dll
2021-06-18 00:45 - 2021-06-18 00:45 - 000025088 _____ (The ICU Project) C:\WINDOWS\system32\icuin.dll
2021-06-18 00:44 - 2021-06-18 00:44 - 000707016 _____ C:\WINDOWS\system32\TextShaping.dll
2021-06-18 00:44 - 2021-06-18 00:44 - 000363520 _____ C:\WINDOWS\system32\Windows.Internal.UI.Shell.WindowTabManager.dll
2021-06-18 00:44 - 2021-06-18 00:44 - 000306688 _____ C:\WINDOWS\system32\HeatCore.dll
2021-06-18 00:44 - 2021-06-18 00:44 - 000165888 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-06-18 00:43 - 2021-06-18 00:43 - 004227116 _____ C:\WINDOWS\system32\DefaultHrtfs.bin
2021-06-18 00:43 - 2021-06-18 00:43 - 000563712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-06-18 00:43 - 2021-06-18 00:43 - 000455168 _____ C:\WINDOWS\system32\ssdm.dll
2021-06-18 00:43 - 2021-06-18 00:43 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll
2021-06-18 00:43 - 2021-06-18 00:43 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-06-18 00:43 - 2021-06-18 00:43 - 000243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\timedate.cpl
2021-06-18 00:43 - 2021-06-18 00:43 - 000197632 _____ C:\WINDOWS\system32\IHDS.dll
2021-06-18 00:43 - 2021-06-18 00:43 - 000089088 _____ C:\WINDOWS\system32\windows.applicationmodel.conversationalagent.proxystub.dll
2021-06-18 00:43 - 2021-06-18 00:43 - 000074240 _____ C:\WINDOWS\system32\rdsxvmaudio.dll
2021-06-18 00:43 - 2021-06-18 00:43 - 000073216 _____ C:\WINDOWS\system32\windows.applicationmodel.conversationalagent.internal.proxystub.dll
2021-06-18 00:43 - 2021-06-18 00:43 - 000064552 _____ C:\WINDOWS\system32\umpdc.dll
2021-06-18 00:43 - 2021-06-18 00:43 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msacm32.drv
2021-06-18 00:43 - 2021-06-18 00:43 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe
2021-06-18 00:21 - 2019-10-15 13:53 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2021-06-18 00:21 - 2019-04-18 18:49 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2021-06-18 00:03 - 2021-06-18 00:03 - 000000000 ____D C:\ProgramData\SetupTPDriver
2021-06-18 00:02 - 2021-06-18 00:02 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2021-06-17 09:06 - 2021-06-17 09:06 - 000001207 _____ C:\Waves MAXXAudio.lnk
2021-06-14 20:06 - 2021-06-14 20:06 - 000000279 _____ C:\Users\gjoas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lixeira.lnk
2021-06-14 11:34 - 2021-06-14 11:40 - 000000000 ____D C:\Users\Public\Documents\iSkysoft
2021-06-14 11:15 - 2021-06-14 12:50 - 000000000 ____D C:\Users\gjoas\Documents\CADERNETA 2021.1
2021-06-13 22:05 - 2021-06-13 22:05 - 003028691 _____ C:\Users\gjoas\Documents\Amor em lágrimas.pdf
2021-06-10 06:03 - 2021-06-29 16:53 - 000000000 ____D C:\Users\gjoas\Desktop\diversos
2021-06-10 06:02 - 2021-06-20 08:19 - 000000000 ____D C:\Users\gjoas\Desktop\piano audição

==================== Um mês (modificados) ==================

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2021-06-30 09:36 - 2019-12-07 06:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-06-30 09:35 - 2021-05-22 09:24 - 000000000 ____D C:\FRST
2021-06-30 08:14 - 2019-12-07 06:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-06-30 08:14 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-06-30 08:11 - 2021-04-28 09:46 - 000000000 ___RD C:\Users\gjoas\OneDrive
2021-06-28 09:08 - 2019-12-07 06:13 - 000000000 ____D C:\WINDOWS\INF
2021-06-27 10:53 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2021-06-27 10:39 - 2019-12-07 11:54 - 000715644 _____ C:\WINDOWS\system32\prfh0416.dat
2021-06-27 10:39 - 2019-12-07 11:54 - 000140800 _____ C:\WINDOWS\system32\prfc0416.dat
2021-06-27 10:31 - 2021-04-28 08:38 - 000008192 ___SH C:\DumpStack.log.tmp
2021-06-27 10:31 - 2019-12-07 06:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-06-27 10:29 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-06-27 10:29 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-06-27 10:29 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-06-27 10:28 - 2019-12-07 06:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-06-27 10:28 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-06-27 10:28 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-06-27 10:28 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-06-27 10:28 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-06-27 10:28 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-06-27 10:28 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-06-27 09:37 - 2019-12-07 06:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-06-27 08:54 - 2019-12-07 06:03 - 000000000 ____D C:\WINDOWS\servicing
2021-06-26 12:33 - 2021-05-16 21:52 - 000000000 ____D C:\Users\gjoas\Documents\certificados
2021-06-26 04:46 - 2021-05-05 06:13 - 000002278 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-06-26 04:46 - 2021-05-05 06:13 - 000002278 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2021-06-26 04:46 - 2021-04-28 08:43 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-06-23 08:15 - 2021-05-04 16:16 - 000000000 ____D C:\Users\gjoas\Documents\AULAS ON LINE
2021-06-21 16:42 - 2021-05-10 15:37 - 000000000 ____D C:\Users\gjoas\Desktop\coro capunga
2021-06-21 13:49 - 2019-12-07 11:54 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2021-06-21 13:49 - 2019-12-07 11:54 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2021-06-21 13:49 - 2019-12-07 11:54 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2021-06-21 13:49 - 2019-12-07 11:54 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2021-06-21 13:49 - 2019-12-07 11:54 - 000000000 ____D C:\WINDOWS\system32\winrm
2021-06-21 13:49 - 2019-12-07 11:54 - 000000000 ____D C:\WINDOWS\system32\WCN
2021-06-21 13:49 - 2019-12-07 11:54 - 000000000 ____D C:\WINDOWS\system32\slmgr
2021-06-21 13:49 - 2019-12-07 11:54 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2021-06-21 13:49 - 2019-12-07 06:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2021-06-21 13:49 - 2019-12-07 06:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2021-06-21 13:49 - 2019-12-07 06:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2021-06-21 13:49 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-06-21 13:49 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2021-06-21 13:49 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2021-06-21 13:49 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2021-06-21 13:49 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2021-06-21 13:48 - 2019-12-07 11:57 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2021-06-21 13:48 - 2019-12-07 11:57 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2021-06-21 13:48 - 2019-12-07 06:14 - 000000000 ___SD C:\WINDOWS\system32\dsc
2021-06-21 13:48 - 2019-12-07 06:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2021-06-21 13:48 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2021-06-21 13:48 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-06-21 13:48 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\IME
2021-06-21 13:48 - 2019-12-07 06:14 - 000000000 ____D C:\Program Files\Windows Defender
2021-06-21 13:48 - 2019-12-07 06:14 - 000000000 ____D C:\Program Files\Common Files\System
2021-06-21 13:48 - 2019-12-07 06:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2021-06-21 13:47 - 2019-12-07 11:56 - 000000000 ____D C:\WINDOWS\OCR
2021-06-21 13:47 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\Com
2021-06-19 17:04 - 2021-04-29 22:36 - 000000000 ____D C:\Users\gjoas\Desktop\Gravações concluídas
2021-06-19 16:31 - 2019-12-07 06:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2021-06-19 16:29 - 2021-05-22 20:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ferramentas do Microsoft Office
2021-06-19 12:53 - 2021-05-26 07:23 - 000000000 ____D C:\Users\gjoas\Documents\Animotica
2021-06-19 11:07 - 2019-12-07 06:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-06-18 06:47 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-06-18 06:41 - 2019-12-07 06:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2021-06-18 06:21 - 2021-04-28 09:40 - 000000000 __RHD C:\Users\Public\AccountPictures
2021-06-18 06:21 - 2021-04-28 09:40 - 000000000 ___RD C:\Users\gjoas\3D Objects
2021-06-18 03:22 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\appcompat
2021-06-18 02:43 - 2019-12-07 06:14 - 000000000 ____D C:\ProgramData\USOPrivate
2021-06-18 02:42 - 2019-12-07 11:55 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2021-06-18 02:42 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\spool
2021-06-18 02:26 - 2019-12-07 06:14 - 000000000 ____D C:\Program Files\Windows NT
2021-06-18 01:40 - 2019-12-07 06:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2021-06-18 01:37 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-06-18 01:22 - 2019-12-07 06:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2021-06-18 01:22 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2021-06-18 01:05 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2021-06-18 01:05 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2021-06-18 01:05 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2021-06-18 01:05 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2021-06-18 01:05 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2021-06-18 01:05 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords
2021-06-18 01:05 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2021-06-18 01:05 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2021-06-18 01:05 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2021-06-18 01:04 - 2019-12-07 11:55 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\Keywords
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2021-06-18 01:04 - 2019-12-07 06:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2021-06-18 01:02 - 2019-12-07 11:57 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2021-06-18 01:02 - 2019-12-07 11:57 - 000020908 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml

==================== SigCheck ============================

(Não há correção automática para arquivos que não passaram na verificação.)

==================== Fim de FRST.txt ========================

"Addition"

Resultado do exame Adicional Farbar Recovery Scan Tool (x64) Versão: 29-06-2021
Executado por gjoas (30-06-2021 09:43:58)
Executando a partir de C:\Users\gjoas\Downloads
Windows 10 Home Single Language Versão 21H1 19043.1081 (X64) (2021-06-18 05:42:26)
Modo da Inicialização: Normal
==========================================================


==================== Contas: =============================

Administrador (S-1-5-21-1057953001-4059818014-1656454705-500 - Administrator - Disabled)
Convidado (S-1-5-21-1057953001-4059818014-1656454705-501 - Limited - Disabled)
DefaultAccount (S-1-5-21-1057953001-4059818014-1656454705-503 - Limited - Disabled)
gjoas (S-1-5-21-1057953001-4059818014-1656454705-1001 - Administrator - Enabled) => C:\Users\gjoas
WDAGUtilityAccount (S-1-5-21-1057953001-4059818014-1656454705-504 - Limited - Disabled)

==================== Central de Segurança ========================

(Se uma entrada for incluída na fixlist, será removida.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}

==================== Programas Instalados ======================

(Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.)

ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.6.8 - ASUSTeK COMPUTER INC.)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 4.0.5 - ASUS)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0039 - ASUS)
Flowgorithm (HKLM\...\{427C418F-9B8F-4021-AFB8-6B202C695E59}) (Version: 2.29.0 - Devin Cook)
Git version 2.32.0 (HKLM\...\Git_is1) (Version: 2.32.0 - The Git Development Community)
Malwarebytes version 4.4.0.117 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.4.0.117 - Malwarebytes)
Microsoft 365 - pt-br (HKLM\...\O365HomePremRetail - pt-br) (Version: 16.0.14026.20308 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 91.0.864.59 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 91.0.864.59 - Microsoft Corporation)
Microsoft OneDrive (HKLM-x32\...\OneDriveSetup.exe) (Version: 21.109.0530.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{E5A95BC5-81DF-4F0C-B910-B59DD012F037}) (Version: 2.81.0.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14026.20308 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14026.20308 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0416-1000-0000000FF1CE}) (Version: 16.0.14026.20246 - Microsoft Corporation) Hidden
Pacote de Driver do Windows - ASUS (ATP) Mouse (06/17/2015 1.0.0.262) (HKLM\...\14588A15B66655338DBCC021FFA81E31DC281859) (Version: 06/17/2015 1.0.0.262 - ASUS)
Portugol Studio (HKLM-x32\...\Portugol Studio 2.7.5) (Version: 2.7.5 - UNIVALI)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9132.1 - Realtek Semiconductor Corp.)

Packages:
=========
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_127.1.115.0_x64__v10z8vjag6ke6 [2021-06-22] (HP Inc.)
RAR Opener -> C:\Program Files\WindowsApps\DeviceDoctor.RAROpener_1.3.48.0_x64__mkdtfchztkfbm [2021-06-19] (Tiny Opener)

==================== Exame Personalizado CLSID (Whitelisted): ==============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-06-19] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\amd64\FileSyncShell64.dll [2021-06-20] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\WINDOWS\system32\igfxpph.dll [2017-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-06-19] (Malwarebytes Corporation -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

==================== Atalhos & WMI ========================

==================== Módulos Carregados (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Modo de Segurança (Whitelisted) ==================

(Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Associação (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKU\S-1-5-21-1057953001-4059818014-1656454705-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-06-19] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts Conteúdo: =========================

(Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.)

2019-12-07 06:14 - 2019-12-07 06:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Outras Áreas ===========================

(Atualmente não há nenhuma correção automática para esta seção.)

HKU\S-1-5-21-1057953001-4059818014-1656454705-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\gjoas\Desktop\EBOOK\DIA E NOITE.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Firewall do Windows está habilitado.

==================== MSCONFIG/TASK MANAGER ítens desabilitados ==

(Se uma entrada for incluída na fixlist, será removida.)

MSCONFIG\Services: cphs => 3
MSCONFIG\Services: DptfParticipantProcessorService => 2
MSCONFIG\Services: DptfPolicyConfigTDPService => 2
MSCONFIG\Services: DptfPolicyCriticalService => 2
MSCONFIG\Services: DptfPolicyLpmService => 2

==================== Regras do Firewall (Whitelisted) ================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

FirewallRules: [{CA75FC97-5BF4-4D96-8288-3358D9507E83}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1E46F7F1-82B2-4727-9F0B-DCA80D54EEE9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{8CE3A3A8-FB33-4D28-A7AF-14BE9386DA07}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{66472E31-EBA4-4F53-9D6D-AD407B54B4C9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{91F8ADDA-7ACE-4DEC-854C-9F175686106A}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{F5B2E186-10D7-42A0-8EE7-E9936AAE974D}C:\users\gjoas\downloads\sdio_1.10.3.732\sdio_1.10.3.732\sdio_x64_r732.exe] => (Allow) C:\users\gjoas\downloads\sdio_1.10.3.732\sdio_1.10.3.732\sdio_x64_r732.exe => Nenhum Arquivo
FirewallRules: [UDP Query User{E5B3D1F7-BC2E-40E4-940F-16CB204C372B}C:\users\gjoas\downloads\sdio_1.10.3.732\sdio_1.10.3.732\sdio_x64_r732.exe] => (Allow) C:\users\gjoas\downloads\sdio_1.10.3.732\sdio_1.10.3.732\sdio_x64_r732.exe => Nenhum Arquivo
FirewallRules: [{0454CEB3-6EDE-494B-BA75-2C3D44F77E0D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{40E75F25-EABE-4A1D-8F05-EB4BD23F4C63}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{603F9C84-C086-4F6E-8A36-A9D28695CD97}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{E4184B73-5CBE-4E00-87FC-A1936DF5AD9A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{BAB17EA3-EB41-46BE-8E9D-7361FA5EE56B}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\91.0.864.59\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{0470BB5A-B9BD-48AC-A095-7F255EE77E12}C:\programdata\univali\portugol studio\java\java-windows\bin\javaw.exe] => (Allow) C:\programdata\univali\portugol studio\java\java-windows\bin\javaw.exe
FirewallRules: [UDP Query User{6C51C644-6692-4116-92FE-52EBBBFEC266}C:\programdata\univali\portugol studio\java\java-windows\bin\javaw.exe] => (Allow) C:\programdata\univali\portugol studio\java\java-windows\bin\javaw.exe

==================== Pontos de Restauração =========================

24-06-2021 18:30:21 Instalador de Módulos do Windows
26-06-2021 16:07:32 Installed Flowgorithm

==================== Dispositivos Apresentando Falhas No Gerenciador ============

Name: Dispositivo USB MTP
Description: Dispositivo USB MTP
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: (Standard MTP-compliant devices)
Service: WUDFRd
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.

Name: Tela touch compatível com HID
Description: Tela touch compatível com HID
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: (Dispositivos padrão do sistema)
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Erros no Log de eventos: ========================

Erros em Aplicativos:
==================
Error: (06/30/2021 08:15:44 AM) (Source: DptfEvent) (EventID: 2) (User: )
Description: Event-ID 2

Error: (06/30/2021 08:15:44 AM) (Source: DptfEvent) (EventID: 3) (User: )
Description: Event-ID 3

Error: (06/29/2021 09:00:03 AM) (Source: DptfEvent) (EventID: 2) (User: )
Description: Event-ID 2

Error: (06/29/2021 09:00:03 AM) (Source: DptfEvent) (EventID: 3) (User: )
Description: Event-ID 3

Error: (06/29/2021 06:03:16 AM) (Source: DptfEvent) (EventID: 2) (User: )
Description: Event-ID 2

Error: (06/29/2021 06:03:16 AM) (Source: DptfEvent) (EventID: 3) (User: )
Description: Event-ID 3

Error: (06/28/2021 07:57:23 AM) (Source: DptfEvent) (EventID: 2) (User: )
Description: Event-ID 2

Error: (06/28/2021 07:57:23 AM) (Source: DptfEvent) (EventID: 3) (User: )
Description: Event-ID 3


Erros de Sistema:
=============
Error: (06/30/2021 09:26:50 AM) (Source: WPDClassInstaller) (EventID: 25088) (User: )
Description: Não foi possível instalar os drivers do dispositivo USB\VID_04E8&PID_6860&REV_0400&MS_COMP_MTP&SAMSUNG_Android. Código do erro 0xe0000217.

Error: (06/30/2021 09:20:30 AM) (Source: WPDClassInstaller) (EventID: 25088) (User: )
Description: Não foi possível instalar os drivers do dispositivo USB\VID_04E8&PID_6860&REV_0400&MS_COMP_MTP&SAMSUNG_Android. Código do erro 0xe0000217.

Error: (06/30/2021 09:20:03 AM) (Source: WPDClassInstaller) (EventID: 25088) (User: )
Description: Não foi possível instalar os drivers do dispositivo USB\VID_04E8&PID_6860&REV_0400&MS_COMP_MTP&SAMSUNG_Android. Código do erro 0xe0000217.

Error: (06/30/2021 08:44:29 AM) (Source: WPDClassInstaller) (EventID: 25088) (User: )
Description: Não foi possível instalar os drivers do dispositivo USB\VID_04E8&PID_6860&REV_0400&MS_COMP_MTP&SAMSUNG_Android. Código do erro 0xe0000217.

Error: (06/30/2021 08:10:02 AM) (Source: WPDClassInstaller) (EventID: 25088) (User: )
Description: Não foi possível instalar os drivers do dispositivo USB\VID_04E8&PID_6860&REV_0400&MS_COMP_MTP&SAMSUNG_Android. Código do erro 0xe0000217.

Error: (06/29/2021 11:26:50 PM) (Source: WPDClassInstaller) (EventID: 25088) (User: )
Description: Não foi possível instalar os drivers do dispositivo USB\VID_04E8&PID_6860&REV_0400&MS_COMP_MTP&SAMSUNG_Android. Código do erro 0xe0000217.

Error: (06/29/2021 11:25:08 PM) (Source: WPDClassInstaller) (EventID: 25088) (User: )
Description: Não foi possível instalar os drivers do dispositivo USB\VID_04E8&PID_6860&REV_0400&MS_COMP_MTP&SAMSUNG_Android. Código do erro 0xe0000217.

Error: (06/29/2021 09:42:34 PM) (Source: WPDClassInstaller) (EventID: 25088) (User: )
Description: Não foi possível instalar os drivers do dispositivo USB\VID_04E8&PID_6860&REV_0400&MS_COMP_MTP&SAMSUNG_Android. Código do erro 0xe0000217.


Windows Defender:
================
Date: 2021-06-19 08:45:28
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {409F60A3-EA54-4245-93F2-71220A926C14}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

Date: 2021-06-19 07:00:52
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {32DDD0D5-3260-40F8-A599-C323DAB194AF}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

Date: 2021-06-19 06:46:00
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {1BE17325-F04E-4EB0-881B-1798360C3845}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

Date: 2021-06-27 10:31:07
Description:
Microsoft Defender Antivírus encontrou um erro ao tentar carregar a inteligência de segurança e tentará reverter para uma versão válida.
Tentativa de Inteligência de Segurança: Backup
Código de Erro: 0x80070013
Descrição do Erro: A mídia está protegida contra gravação.
Versão da Inteligência de Segurança: 1.341.1224.0;1.341.1224.0
Versão do Mecanismo: 1.1.18200.4

Date: 2021-06-27 10:31:05
Description:
Microsoft Defender Antivírus encontrou um erro ao tentar carregar a inteligência de segurança e tentará reverter para uma versão válida.
Tentativa de Inteligência de Segurança: Atual
Código de Erro: 0x80508001
Descrição do Erro: Um problema está impedindo que o programa seja iniciado. Instale as atualizações disponíveis e tente iniciar o programa novamente. Para obter informações sobre como instalar atualizações, consulte Ajuda e Suporte.
Versão da Inteligência de Segurança: 1.341.1288.0;1.341.1288.0
Versão do Mecanismo: 1.1.18200.4

==================== Informações da Memória ===========================

BIOS: American Megatrends Inc. S400CA.209 05/14/2013
placa-mãe: ASUSTeK COMPUTER INC. S400CA
Processador: Intel(R) Core(TM) i3-2365M CPU @ 1.40GHz
Percentagem de memória em uso: 84%
RAM física total: 3979.7 MB
RAM física disponível: 614.14 MB
Virtual Total: 5515.7 MB
Virtual disponível: 1641.5 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:185.75 GB) (Free:140.98 GB) NTFS ==>[sistema com componentes de inicialização (obtido através de drive)]
Drive d: (Data) (Fixed) (Total:258.15 GB) (Free:257.62 GB) NTFS

\\?\Volume{02a872f0-ecf8-4895-8882-01d801188efd}\ (Recovery) (Fixed) (Total:0.88 GB) (Free:0.53 GB) NTFS
\\?\Volume{e2dd49ec-1fdb-443f-8ce6-3126411be6bc}\ () (Fixed) (Total:0.55 GB) (Free:0.08 GB) NTFS
\\?\Volume{26b214db-8350-4c97-be05-8d0a1e4b7944}\ (Restore) (Fixed) (Total:20.01 GB) (Free:9.6 GB) NTFS
\\?\Volume{7ea8aed6-6492-4a25-8f2f-13594197af39}\ (SYSTEM) (Fixed) (Total:0.29 GB) (Free:0.26 GB) FAT32

==================== MBR & Tabela de Partições ====================

==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 0D7C9FC3)

Partition: GPT.

==================== Fim de Addition.txt =======================
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#7 Por joram
01/07/2021 - 15:05
/!\ Boa Tarde! etm /!\

Como sugerido,altere a senha do facebook.

> Copie estas informações que estão no Spoiler,para o Bloco de Notas.
> Salve-as com o nome fixlist. << Texto ou Unicode,caso solicite!
> Salve-as ao desktop! ( Área de trabalho ... )
> Ps: Em seu caso,na pasta Downloads!

Imagem
[spoiler]start::
CloseProcesses:
CMD: netsh int ip reset all
CMD: ipconfig /flushdns
StartPowershell:
sfc /scannow
EndPowershell:
EmptyTemp:
Hosts:
Reboot:
end::
[/spoiler]

Imagem

> Execute FRST/FRST64 >> Clique "Corrigir" << Aguarde!
> Poste o relatório "Resultado da Correção pela Farbar Recovery Scan Tool". (Fixlog.txt)
> Este e outros relatórios,podem ser encontrados na pasta: Disco Local (C) > FRST > Logs

< Este script foi elaborado exclusivamente para este computador,portanto peço aos visitantes que não o utilize em outras "máquinas". >

[]s
etm
etm Membro Junior Registrado
82 Mensagens 18 Curtidas
#8 Por etm
02/07/2021 - 14:13
joram disse:
/!\ Boa Tarde! etm /!\

Como sugerido,altere a senha do facebook.

Feito!

> Copie estas informações que estão no Spoiler,para o Bloco de Notas.
> Salve-as com o nome fixlist. << Texto ou Unicode,caso solicite!
> Salve-as ao desktop! ( Área de trabalho ... )
> Ps: Em seu caso,na pasta Downloads!

Imagem
[spoiler]start::
CloseProcesses:
CMD: netsh int ip reset all
CMD: ipconfig /flushdns
StartPowershell:
sfc /scannow
EndPowershell:
EmptyTemp:
Hosts:
Reboot:
end::
[/spoiler]

Imagem

> Execute FRST/FRST64 >> Clique "Corrigir" << Aguarde!
> Poste o relatório "Resultado da Correção pela Farbar Recovery Scan Tool". (Fixlog.txt)
> Este e outros relatórios,podem ser encontrados na pasta: Disco Local (C) > FRST > Logs

< Este script foi elaborado exclusivamente para este computador,portanto peço aos visitantes que não o utilize em outras "máquinas". >

[]s


Segue o relatório:
"Relatório da correção"

Resultado da Correção pela Farbar Recovery Scan Tool (x64) Versão: 01-07-2021
Executado por gjoas (02-07-2021 13:37:17) Run:2
Executando a partir de C:\Users\gjoas\Downloads
Perfis Carregados: gjoas
Modo da Inicialização: Normal
==============================================

fixlist Conteúdo:
*****************
CloseProcesses:
CMD: netsh int ip reset all
CMD: ipconfig /flushdns
StartPowershell:
sfc /scannow
EndPowershell:
EmptyTemp:
Hosts:
Reboot:

*****************

Processos fechados com sucesso.

========= netsh int ip reset all =========

Redefinindo Encaminhamento de Compartimento, OK!
Redefinindo Compartimento, OK!
Redefinindo Protocolo de Controle, OK!
Redefinindo Solicita‡Æo de Sequˆncia de Eco, OK!
Redefinindo Global, OK!
Redefinindo Interface, OK!
Redefinindo Endere‡o Anycast, OK!
Redefinindo Endere‡o multicast, OK!
Redefinindo Endere‡o Unicast, OK!
Redefinindo Vizinho, OK!
Redefinindo Caminho, OK!
Redefinindo Potencial, OK!
Redefinindo Pol¡tica de Prefixo, OK!
Redefinindo Vizinho de Proxy, OK!
Redefinindo Rota, OK!
Redefinindo Prefixo do Site, OK!
Redefinindo Subinterface, OK!
Redefinindo PadrÆo de Ativa‡Æo, OK!
Redefinindo Resolver Vizinho, OK!
Redefinindo , OK!
Redefinindo , OK!
Redefinindo , OK!
Redefinindo , OK!
Falha ao redefinir .
Acesso negado.

Redefinindo , OK!
Redefinindo , OK!
Redefinindo , OK!
Redefinindo , OK!
Redefinindo , OK!
Redefinindo , OK!
Redefinindo , OK!
Reinicie o computador para concluir esta a‡Æo.


========= Fim de CMD: =========


========= ipconfig /flushdns =========


Configura‡Æo de IP do Windows

Libera‡Æo do Cache do DNS Resolver bem-sucedida.

========= Fim de CMD: =========


========= Powershell: =========




I n i c i a n d o v e r i f i c a þ Ò o d e a r q u i v o s . O p r o c e s s o l e v a r ß a l g u n s m i n u t o s p a r a s e r c o n c l u Ý d o .





I n i c i a n d o f a s e d e v e r i f i c a þ Ò o d e v e r i f i c a þ Ò o d o s i s t e m a .



V e r i f i c a þ Ò o 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 2 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 3 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 4 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 5 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 6 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 7 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 8 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 0 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 1 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 2 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 3 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 4 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 5 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 6 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 7 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 8 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 9 9 % c o n c l u Ý d a .
V e r i f i c a þ Ò o 1 0 0 % c o n c l u Ý d a .




A P r o t e þ Ò o d e R e c u r s o s d o W i n d o w s e n c o n t r o u a r q u i v o s c o r r o m p i d o s e o s r e p a r o u c o m Û x i t o .


P a r a r e p a r o s o n l i n e , o s d e t a l h e s s Ò o i n c l u Ý d o s n o a r q u i v o d e l o g C B S l o c a l i z a d o e m


w i n d i r \ L o g s \ C B S \ C B S . l o g . P o r e x e m p l o , C : \ W i n d o w s \ L o g s \ C B S \ C B S . l o g . P a r a r e p a r o s


o f f l i n e , o s d e t a l h e s s Ò o i n c l u Ý d o s n o a r q u i v o d e l o g f o r n e c i d o p e l o s i n a l i z a d o r / O F F L O G F I L E .




========= Fim de Powershell: =========

C:\Windows\System32\Drivers\etc\hosts => movido com sucesso
Hosts restaurado com sucesso.

=========== EmptyTemp: ==========

BITS transfer queue => 7888896 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 83968508 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 61743194 B
Edge => 0 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 78448 B
NetworkService => 138774 B
gjoas => 323139602 B

RecycleBin => 0 B
EmptyTemp: => 454.9 MB de dados temporários Removidos.

================================


O sistema precisou ser reiniciado.

==== Fim de Fixlog 13:59:15 ====
etm
etm Membro Junior Registrado
82 Mensagens 18 Curtidas
#10 Por etm
02/07/2021 - 16:00
joram disse:
/!\ Boa Tarde! etm /!\




> Instale ao navegador este complemento: Imagem

> O link àcima é complemento para ser instalado no Edge.

> Tudo Ok?

[]s


Boa tarde,
Feito.bom_trabalho.gif
Aqui tudo certo.
Valeu!!isso_ai.png

editando:
Descubro hoje, três páginas curtidas por "mim" em horários diferentes, que não fui eu.
Aguardando mais sugestões.choramingando.gif

Obs.: Alguma chance de ser pelo celular essa "invasão"?
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#11 Por joram
03/07/2021 - 09:01
/!\ Bom Dia! etm /!\
Obs.: Alguma chance de ser pelo celular essa "invasão"?
Imagem das páginas curtidas
https://ibb.co/YpK0tYW

Se houve sincronização,ao instalar algum navegador,o celular é caminho suspeito.

Imagem

Ps: O link que postou indicando as imagens curtidas,meu 360 apontou site de phishing.
Especificamente o 360safe.com,que o 360 disponibiliza para proteção ao browser.

[]s
etm
etm Membro Junior Registrado
82 Mensagens 18 Curtidas
#12 Por etm
03/07/2021 - 09:45
joram disse:
/!\ Bom Dia! etm /!\

Se houve sincronização,ao instalar algum navegador,o celular é caminho suspeito.

Imagem

Ps: O link que postou indicando as imagens curtidas,meu 360 apontou site de phishing.
Especificamente o 360safe.com,que o 360 disponibiliza para proteção ao browser.

[]s


Sinto muito pelo link....Não sabia. Desculpas.

Quanto ao celular, eu baixei um antivirus para verificar alguma coisa. Baixei o AVG. Não sei se este é o caminho.
@joram
Agradeço. Acredito que já está tudo resolvido. Esqueci de um detalhe, e não houve mais "invasão" durante este dia: foi colocar o login em duas etapas de confirmação.

Valeu, pessoal!
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal